daily cyber × ai intelligence

index

tagged

[icarus]

6 editions · 3 items

June 24, 2026

Two Netlogon Flaws Hit Domain Controllers as FortiBleed Lands in Finland

Critical vulnerabilities hit domain controllers as CVE-2026-41089 (Netlogon RCE) and Onelogon (Zerologon bypass) emerge, while FortiBleed credential-harvesting campaign reaches Finnish organizations after compromising 110M+ credentials from 430K+ Fortinet devices. Major supply-chain threats include Klue OAuth attacks affecting LastPass, malicious npm packages impersonating PostCSS, and Cordyceps malicious pull requests targeting Azure/Google/Apache projects; Anthropic's Mythos model discovered Squidbleed (Heartbleed-style flaw in Squid) and vulnerabilities in classified US systems.

June 23, 2026

  • Klue breach fallout widens to a who's-who of security vendors — after Icarus posted stolen data on June 22, affected Klue customers now include HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium. Huntress says no product data, telemetry, passwords, or card data were touched — exposure is limited to business metadata (names, products trialed, subscription/pricing, sales notes) — and warns the data is ripe for Klue/Huntress impersonation. SecurityWeek · Huntress · Threat Intelligence

in Five Eyes Warns Frontier AI Will Reshape Offensive Cyber Ops as a New Entra ID Conditional Access Bypass Surfaces

June 21, 2026

  • Klue, a competitive-intelligence platform, confirmed attackers stole OAuth tokens used to connect to customers' Salesforce environments, and the new Icarus extortion group has claimed it (BleepingComputer). Salesforce disabled the Klue Battlecards integration on June 11; this is the third Salesforce-connected app abused for CRM data theft, and confirmed victims include security vendors Huntress and Recorded Future (SecurityWeek, The Hacker News). · Cloud & Identity

in FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog

June 20, 2026

FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token

FortiBleed has compromised ~86,644 internet-facing FortiGate devices in a credential-harvesting campaign, while a leaked GitHub token gave FulcrumSec access to Novo Nordisk, exfiltrating 1.3TB including unreleased drug formulas and internal AI models. Mastra npm packages were trojanized by Sapphire Sleet (North Korea–nexus), and multiple AI infrastructure flaws emerged: SearchLeak (CVE-2026-42824) in Microsoft 365 Copilot, Pickle in the Middle in Google Vertex AI, and vulnerabilities in LiteLLM. Ransomware gangs including Qilin, Gentlemen, and DragonForce continue dominating the threat landscape with EDR-killing tradecraft and cloud-based C2 abuse.

June 19, 2026

FortiBleed Burns 70,000+ Fortinet Edge Devices While a Leaked GitHub Token Guts Novo Nordisk

FortiBleed exposed working SSL-VPN credentials for 70,000+ Fortinet devices across 194 countries via industrialized hash-cracking by a Russian-speaking group, while a forgotten GitHub token cost Novo Nordisk 1.3TB of drug formulas and internal AI models. Critical vulnerabilities in NGINX (CVE-2026-42530), Cisco SD-WAN and ISE, Splunk, and Joomla are under active exploitation, alongside AI pipeline supply-chain attacks hitting Mastra, JetBrains Marketplace, and Google Vertex AI. The AtomicArch campaign compromised ~1,500 Arch Linux AUR packages with Rust infostealers and eBPF rootkits.