
Hello all,
Last weekend a LinkedIn post alerted the world to a database of Fortinet credentials on the internet. This week it exploded into a major issue now named FortiBleed. More on that in a moment. CISA issued orders that several products needed to be patched by Sunday June 21, 2026. At least they get the longest day of the year to get it done. Anthropic’s Claude Fable 5 is still shutdown word wide with no news as to when it, or a more secure variant, may reappear. And of course we have lots of other news items to skim and digest.
Headline NEWS:
- F5 networks released an out-of-band patch for critical NGINX defects. The most severe can enable a threat actor to execute code on vulnerable systems. There is some mitigation guidance in case you can’t apply the update immediately. It would be wise to address this quickly since evil people are actively prowling for these types of vulnerabilities.
- Fortinet FortiBleed exploded into the consciousness of most cybersecurity professionals this past week when the scope of this massive active credential harvesting and exposure began to be fully understood. There are over 21,000 different domain names listed along with over 84,000 credentials. Companies such as Chevron, Spotify, Samsung, Oracle, Lenovo, FedEx, ADP, Siemens, TP-Link, Netgear, DHL, and many more major brands are listed among the victims. Many have already had threat actors rummaging around doing nefarious things in their networks via these credentials, others are yet to be utilized. The race is now on for anyone with a Fortinet firewall to rotate credentials, enforce MFA, and follow additional vendor guidance to secure their firewalls. This is as critical as it gets. And if that wasn’t enough, Fortinet published that FortiSandbox is now under active exploitation. There is a patch available, so if you have this, patch it immediately.
In Ransomware, Malware, and Vulnerabilities News:
- Klue an intelligence collection and analysis engine that ties into many companies’ Salesforce data was breached a little over a week ago via their “Battlecards app”. It is suspected that hundreds of companies, including at least seven security vendors, may have had data potentially harvested by the dirtbag group known as Icarus. Salesforce has shut down the integration, and forensic work is now underway to determine the scope of the breach. This will be one to follow since Klue also had integrations with other vendors such as HubSpot, Microsoft SharePoint, Zoom, and Google Drive.
In Other News Events of Note and Interest:
- Broadcom continues to tick off longtime VMware clients with their inflexible egregious price increases. UK retail giant Tesco has had enough and is jumping ship with its 40,000 servers. For Broadcom’s part, their strategy is actually paying off to some degree, significantly fewer clients to support, but higher revenue is coming in. It will be interesting to see if that will sustain long-term, or are the ones paying the massively jacked up prices actively migrating and plan to drop VMware as soon as they’re able.
Musings
This coming Sunday, June 21, 2026, is Father’s Day in the US, and it is the longest day of the year, the Summer Solstice. I hope that the dad’s out there get a bit of extra sunshine to enjoy their day, their children and computers cooperate with them, and may they always…

Keep the shields up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- F5 issues out-of-band patches for critical NGINX vulnerabilities
- Critical Fortinet FortiSandbox flaws now exploited in attacks
- FortiBleed — 75k Fortinet firewalls have admin passwords cracked
- FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices
- Massive breach spills credentials for thousands of sensitive networks
- CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
Ransomware, Malware, and Vulnerabilities News
- Good News, Government News, and Interesting
- Bill aims to centralize government efforts to fight online fraud
- CISA Issues New Directive Improving How Federal Agencies Prioritize the Mitigation of Cyber Vulnerabilities
- White House Issues Memo to Bolster NSS Cybersecurity
- FBI takes down massive China-based cybercrime network that caused $1.9B in losses
- FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service
- INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator
- Vulnerabilities and Exploits
- Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
- Palo Alto Warns GlobalProtect VPN Flaw Is Being Actively Exploited
- Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
- Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
- CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
- CISA orders feds to patch actively exploited Ivanti flaw by Sunday
- CISA: Splunk Enterprise flaw actively exploited, patch by Sunday
- OptinMonster WordPress plugin hacked in CDN supply-chain attack
- SimpleHelp bug lets hackers create rogue remote support accounts
- CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation
- China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
- GhostTree Attack Abused Recursive Windows Junctions to Hide Malware
- Apple A12 and A13 devices face unpatchable ROM vulnerability
- Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone
- A 27-Year-Old Authentication Bypass in OpenBSD’s PPP Stack
- Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
- Supply chain attacks: the third-party risks to your business
- GlobalSign Revokes EV Certificates From Sanctioned Firms
- Multiple Vulnerabilities in Firefox 152 Enables Remote Code Execution Attacks
- Phishing, Malware, and Similar
- Sri Lanka sees ‘alarming’ rise in cybercrime as scam networks relocate from south-east Asia | Sri Lanka
- Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware
- ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures
- ‘Lorem Ipsum’ Malware Pivots to ClickFix Delivery
- Threat Actor Malware Platform Exposed via Unlocked PHP Installation Page
- Kaspersky finds malware hidden in Steam Wallpaper Engine that hijacks accounts to spread itself
- Fake Boots emails target millions in large phishing campaign
- Asia-Pacific scam networks generate nearly $40 billion a year
- Microsoft links Mastra AI supply chain attack to North Korean hackers
- Breaches, Leaks, and Ransomware
- Maine takes down its data breach notification portal after it is flooded by fake claims
- Infinite Campus data breach affects 137,000 school staff accounts
- Council of Europe hacked in ShinyHunters’ PeopleSoft heist
- ShinyHunters Claims Council of Europe Hack
- Novo Nordisk says hackers stole clinical trial data
- iRhythm discloses data breach, says hackers stole patient info
- Ransomware gang abuses Microsoft Teams relays to hide malicious traffic
- DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
- Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase
- Chinese hackers hijack auth flow, spy on isolated network for a decade
- China-Nexus Actor Spies on US Researchers Undetected for a Year
- Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer
- Cardiac patients’ medical data stolen and held to ransom
- Kodak confirms data breach claimed by ShinyHunters extortion gang
- 124 million passwords added to breach database. Yours may be in there, too
- INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023
- Gentlemen ransomware uses multiple EDR killers to disable defenses
- Nintendo confirms data stolen in WebMD subsidiary cyberattack
- Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress
- Salesforce Data Thefts Continue via Klue App Compromise
- New Prinz Eugen ransomware prioritizes recent files for encryption
Other News Events of Note and Interest
- Cool Tool – Winhance 26.06.12
- Tesco moving 40,000 server workloads off VMware amid Broadcom’s “abusive conduct”
- US decision to block Mythos access fuels European calls for sovereignty
- World leaders want American AI. They just don’t want America to be able to turn it off.
- France’s digital sovereignty push is struggling to escape the Microsoft gravity well
- France to stop certifying products without quantum-safe encryption
- Oracle wins $396M federal HR software contract
- Brain-computer interface enables independent, accurate communication for man living with ALS
- Starmer announces UK social media ban for under-16s
- Australia’s social media ban shows UK child safety measures are bound to fail — and it’s not because of VPNs
- Student Reading Ability Spikes After Removing Tech From Class
- Cloudflare DMARC Management is now generally available
- The $3 ChromeOS Flex USB kit is back in stock at Back Market
- Hand gesture verification | Google Cloud Fraud Defense
- Windows and Linux users: The deadline to update Secure Boot keys is near
- AI, LLM’s, and Skynet
- Banning Mythos represents a basic misunderstanding of AI cybersecurity
- Anthropic, Trump Officials Seek Deal on Restoring Powerful Model Access
- Early users of Anthropic’s Mythos still have access after US order, Bloomberg News reports
- Anthropic’s Safety Superpower
- Report: Microsoft Restricts Employees’ Claude Access Over Data Retention
- 5 runtime signals for catching a compromised AI agent
- Google Cloud Announces The Open Knowledge Format
- SpaceX to acquire the AI coding startup Cursor for $60 billion
- Facebook Gets its Own AI Mode for Search: How It Works
- Most pros have seen AI hallucinations in IT operations
- Low-skilled attacker used Claude, Codex to breach 14 companies
- Microsoft turns to AWS as GitHub faces AI capacity crunch
- AI agents put cybersecurity frameworks to the test
- Microsoft
- Microsoft site throwing warnings after someone forgot to renew cert
- Windows 11 KB5094126, KB5093998 bugging out Office apps but it may not be Microsoft’s fault
- Microsoft fixes Windows Server 2016 security update failures
- Microsoft Defender for Office 365 Plan 1 is now rolling out to Microsoft 365 E3 and Office 365 E3
- Microsoft confirms Recycle Bin bug across all versions of Windows
- Microsoft confirms Windows 11 26H2, urges IT admins to prepare for release
- I ran a free Microsoft tool and found 161 startup entries Task Manager couldn’t see
