threat-intel FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation A Russian-speaking threat actor, dubbed FortiBleed, is conducting a large-scale credential harvesting operation targeting over 430,000 FortiGate firewalls globally. The campaign, active since February 2026, utilizes a Go… The Hacker News · Jun 23, 2026 High USINRUcredential harvestingfirewallactive directory
threat-intel FortiBleed Attackers Turn Firewalls Into Credentials Stealers as Heist Persists The FortiBleed campaign, spearheaded by threat actors likely originating from Russia, has compromised over 430,000 FortiGate firewalls globally, resulting in the theft of more than 110 million credentials. Attackers util… Dark Reading · Jun 23, 2026 High USRUINcredential theftfirewallauthentication
threat-intel Russian Initial Access Broker Behind FortiBleed Campaign A Russian initial access broker (IAB) is targeting over 430,000 FortiGate firewalls globally as part of the FortiBleed campaign, harvesting credentials and selling access to other malicious actors. The campaign utilizes… SecurityWeek · Jun 23, 2026 High USGBNLcredential harvestingfirewallsupply chain
malware WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool A WhatsApp-based campaign is utilizing malicious VBScript files to trick users into installing ManageEngine RMM tool software. The campaign, currently active across multiple countries, leverages deceptive document names… The Hacker News · Jun 23, 2026 Medium MYBRINsocial engineeringvbsremote access
malware A VBScript campaign distributed through WhatsApp deploying RMM software A WhatsApp-distributed malware campaign, active as of June 2026, leverages deceptive VBScript files disguised as financial documents to trick users into executing malicious code. This code ultimately installs legitimate… Securelist · Jun 22, 2026 High MYBRINsocial engineeringvbswhatsapp
threat-intel French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation This article reports on a discussion at the G7 summit regarding the regulation of advanced artificial intelligence (AI) systems, particularly focusing on the U.S. government’s restriction on access to Anthropic’s latest… SecurityWeek · Jun 20, 2026 Medium FRUNCAaiartificial intelligenceregulation
threat-intel Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites An international law enforcement operation, dubbed Operation Endgame, successfully disrupted SocGholish’s infrastructure and removed malware from nearly 15,000 WordPress websites. The takedown, involving agencies from mu… The Hacker News · Jun 19, 2026 High NLCADEbotnetwordpressmalware
threat-intel CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices CISA has issued a warning to Fortinet customers regarding FortiBleed, a campaign targeting 86,644 FortiGate devices globally. The attack, attributed to Russian-speaking threat actors, leverages a two-step approach involv… The Hacker News · Jun 19, 2026 High USINMEcredential_stuffingdefault_credentialspassword_reuse
threat-intel CISA warns Fortinet users to secure devices after FortiBleed leak CISA has issued a warning to Fortinet customers regarding the "FortiBleed" data leak, which exposed nearly 74,000 firewall and VPN credentials. Threat actors are exploiting these compromised credentials to target interne… BleepingComputer · Jun 19, 2026 High USRUCNcredentialsvpnfirewall
threat-intel Close Encounters of the Human Kind This article from Cisco Talos details a novel approach to reverse engineering that leverages AI agents alongside traditional tools like the VB6 disassembler. The key innovation is exposing the disassembler's parsed data… Cisco Talos · Jun 18, 2026 High GBFRUSreverse engineeringaiautomation
threat-intel ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories This week’s ThreatDay Bulletin highlights several concerning security incidents, including browser extension abuse, macOS malware attacks, AI-powered malware delivery, and a global phishing campaign targeting travel book… The Hacker News · Jun 18, 2026 High CVE-2026-20127CVE-2026-49975USCNJPbrowser extensionsmacos malwareai abuse
threat-intel Telegram admits it couldn't police exam-leak channels, India tells court India's government blocked Telegram access following reports of leaked exam materials for the NEET-UG 2026 medical entrance exam, leading to disruptions for users globally. Telegram initially admitted limitations in proa… BleepingComputer · Jun 18, 2026 Medium INAEexamleakregulatory
vulnerability Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT This CISA advisory details a vulnerability in the Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT, specifically version 0x0110_v1.1.0. The device is susceptible to unauthorized interception of sensitive health… CISA Advisories · Jun 18, 2026 High CVE-2026-50034CVE-2026-52866INbluetoothbleglucose
data-breach FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. A significant data leak, dubbed "FortiBleed," has exposed approximately 73,932 Fortinet VPN credentials for firewall URLs across numerous organizations worldwide. The leak, discovered by Bob Diachenko, reveals a multi-op… BleepingComputer · Jun 17, 2026 High USGBJPvpncredentialsbreach
threat-intel India's Telegram ban hit the UAE too. Here's how to get around it Following the ban of Telegram in India due to leaked exam materials from the NEET medical entrance exam, the platform experienced disruptions in access for users globally, notably in the UAE, attributed to a BGP hijackin… BleepingComputer · Jun 17, 2026 High INAEbgproutingexam fraud
threat-intel Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices A large-scale cyber espionage campaign has compromised over 30,000 Fortinet firewalls and VPN gateways globally, harvesting credentials for devices across nearly 200 countries. The operation, believed to be conducted by… Dark Reading · Jun 17, 2026 Critical USINGBcredential-harvestingpassword-compromiseautomation
vulnerability 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs Recent analysis reveals that three previously patched Fortinet FortiSandbox vulnerabilities – CVE-2026-39808, CVE-2026-39813, and CVE-2026-25089 – are actively being exploited in the wild. A significant number of comprom… SecurityWeek · Jun 17, 2026 High CVE-2026-39808CVE-2026-39813CVE-2026-25089USINALvulnerabilitypatchingexploitation
threat-intel India temporarily blocks Telegram over medical exam cheating fears India temporarily blocked access to the Telegram messaging app due to concerns about cheating during a nationwide rerun of the NEET-UG medical entrance exam. Authorities cited instances of scammers using Telegram to dist… The Record · Jun 16, 2026 Medium INtelegramexamcheating
threat-intel North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels North Korean threat actors, operating under the UNK_DeadDrop campaign, are employing a sophisticated phishing technique targeting developers across numerous sectors, including finance and cryptocurrency, using malicious… The Hacker News · Jun 15, 2026 High USGBAUdevelopergithubvscode
threat-intel Phishing Attack Volume Down 20%, but Risk Still Rising The volume of phishing attacks has decreased by 20% across multiple industries, despite a shift towards more sophisticated attacks utilizing AI. Threat actors are prioritizing targeted campaigns with higher conversion ra… Dark Reading · Jun 12, 2026 High CAESAUphishingaicloud