June 24, 2026
Critical vulnerabilities hit domain controllers as CVE-2026-41089 (Netlogon RCE) and Onelogon (Zerologon bypass) emerge, while FortiBleed credential-harvesting campaign reaches Finnish organizations after compromising 110M+ credentials from 430K+ Fortinet devices. Major supply-chain threats include Klue OAuth attacks affecting LastPass, malicious npm packages impersonating PostCSS, and Cordyceps malicious pull requests targeting Azure/Google/Apache projects; Anthropic's Mythos model discovered Squidbleed (Heartbleed-style flaw in Squid) and vulnerabilities in classified US systems.
June 23, 2026
- Klue breach fallout widens to a who's-who of security vendors — after Icarus posted stolen data on June 22, affected Klue customers now include HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium. Huntress says no product data, telemetry, passwords, or card data were touched — exposure is limited to business metadata (names, products trialed, subscription/pricing, sales notes) — and warns the data is ripe for Klue/Huntress impersonation. SecurityWeek · Huntress
· Threat Intelligence
in Five Eyes Warns Frontier AI Will Reshape Offensive Cyber Ops as a New Entra ID Conditional Access Bypass Surfaces
June 22, 2026
- Icarus ransomware escalated supply-chain extortion against a major Canadian consulting/competitive-intelligence firm, now threatening to publish downstream client data — the same actor named in the Klue incident. Ido Cohen.
· Threat Activity & CTI
in Unpatchable iPhone BootROM Exploit Drops as a New Call-Stack Bypass Defeats 2024-Era EDR
June 21, 2026
- Klue, a competitive-intelligence platform, confirmed attackers stole OAuth tokens used to connect to customers' Salesforce environments, and the new Icarus extortion group has claimed it (BleepingComputer). Salesforce disabled the Klue Battlecards integration on June 11; this is the third Salesforce-connected app abused for CRM data theft, and confirmed victims include security vendors Huntress and Recorded Future (SecurityWeek, The Hacker News).
· Cloud & Identity
in FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog
June 20, 2026
FortiBleed has compromised ~86,644 internet-facing FortiGate devices in a credential-harvesting campaign, while a leaked GitHub token gave FulcrumSec access to Novo Nordisk, exfiltrating 1.3TB including unreleased drug formulas and internal AI models. Mastra npm packages were trojanized by Sapphire Sleet (North Korea–nexus), and multiple AI infrastructure flaws emerged: SearchLeak (CVE-2026-42824) in Microsoft 365 Copilot, Pickle in the Middle in Google Vertex AI, and vulnerabilities in LiteLLM. Ransomware gangs including Qilin, Gentlemen, and DragonForce continue dominating the threat landscape with EDR-killing tradecraft and cloud-based C2 abuse.
June 19, 2026
FortiBleed exposed working SSL-VPN credentials for 70,000+ Fortinet devices across 194 countries via industrialized hash-cracking by a Russian-speaking group, while a forgotten GitHub token cost Novo Nordisk 1.3TB of drug formulas and internal AI models. Critical vulnerabilities in NGINX (CVE-2026-42530), Cisco SD-WAN and ISE, Splunk, and Joomla are under active exploitation, alongside AI pipeline supply-chain attacks hitting Mastra, JetBrains Marketplace, and Google Vertex AI. The AtomicArch campaign compromised ~1,500 Arch Linux AUR packages with Rust infostealers and eBPF rootkits.