daily cyber × ai intelligence

index

tagged

[squid]

2 editions · 1 item

June 24, 2026

Two Netlogon Flaws Hit Domain Controllers as FortiBleed Lands in Finland

Critical vulnerabilities hit domain controllers as CVE-2026-41089 (Netlogon RCE) and Onelogon (Zerologon bypass) emerge, while FortiBleed credential-harvesting campaign reaches Finnish organizations after compromising 110M+ credentials from 430K+ Fortinet devices. Major supply-chain threats include Klue OAuth attacks affecting LastPass, malicious npm packages impersonating PostCSS, and Cordyceps malicious pull requests targeting Azure/Google/Apache projects; Anthropic's Mythos model discovered Squidbleed (Heartbleed-style flaw in Squid) and vulnerabilities in classified US systems.

June 23, 2026

  • Squidbleed: 29-year-old Squid proxy heap over-read leaks cleartext HTTP — Calif.io disclosed a Heartbleed-style bug (traced to a 1997 FTP-parsing change) that can leak another user's request — including credentials or session tokens — to anyone allowed through the same proxy. Live in Squid's default config. The Hacker News · SecurityWeek · Vulnerabilities & Exploits

in Five Eyes Warns Frontier AI Will Reshape Offensive Cyber Ops as a New Entra ID Conditional Access Bypass Surfaces