CVE-2023-3519, CVE-2023-48788, CVE-2023-52271, CVE-2024-57727, CVE-2025-1055, CVE-2025-13036, CVE-2025-20700, CVE-2025-20701, CVE-2025-20702, CVE-2025-36539, CVE-2025-44019, CVE-2025-5777, CVE-2025-61155, CVE-2026-10275, CVE-2026-12087, CVE-2026-12390, CVE-2026-20253, CVE-2026-32174, CVE-2026-32208, CVE-2026-40624, CVE-2026-42014, CVE-2026-42055, CVE-2026-42530, CVE-2026-42895, CVE-2026-42945, CVE-2026-43966, CVE-2026-44967, CVE-2026-47633, CVE-2026-47646, CVE-2026-4827, CVE-2026-48914, CVE-2026-50034, CVE-2026-52866, CVE-2026-53689, CVE-2026-6865, CVE-2026-8805, CVE-2026-8806, CVE-2026-9669
IP Addresses:
37.0.2.1
Get tomorrow's brief in your inbox
June 19, 2026
Today: CISA adds actively exploited Splunk vulnerability to its KEV catalog days after disclosure. Fortinet FortiBleed credential exposure impacts 74,000 devices across 194 countries as attackers leverage plaintext VPN credentials. Operation Endgame disrupts SocGholish infrastructure after years of website compromise campaigns. INC ransomware claims 830 victims since 2023, emerging as a top RaaS operation. Supply chain attacks compromise ShapedPlugin and Klue, granting attackers access to WordPress sites and Salesforce data.
Splunk Enterprise Authentication Bypass (CVE-2026-20253)
Splunk Enterprise has a critical authentication bypass vulnerability under active exploitation in the wild. The flaw exists in a PostgreSQL sidecar service endpoint that lacks authentication controls, allowing any network-reachable attacker to create or truncate arbitrary files. Researchers published proof-of-concept code demonstrating remote code execution on June 12, and exploitation was confirmed by Splunk on June 18. CISA added CVE-2026-20253 to its Known Exploited Vulnerabilities catalog, the first Splunk flaw ever added to the KEV list.
FortiBleed: 74,000 Fortinet Devices Compromised
A massive credential exposure dubbed FortiBleed has leaked plaintext passwords for 73,932 Fortinet FortiGate firewalls and VPN gateways worldwide. The dataset includes usernames, email addresses, and plaintext passwords for devices spanning 21,632 unique domains across 194 countries. Victims include Samsung, Mercedes-Benz, Foxconn, Chevron, Comcast, AT&T, Toyota, and numerous government agencies. Security researchers confirmed the credentials are valid and most affected devices remain online. The operation was conducted by a Russian-speaking threat group that performed approximately 1.16 billion credential attempts against 320,000 FortiGate targets to intercept SSL VPN authentication hashes.
F5 NGINX Critical Remote Code Execution Flaws
F5 patched two critical vulnerabilities in NGINX Open Source that enable remote code execution. CVE-2026-42530 (CVSS 9.2, EPSS 97th percentile) is a use-after-free in the HTTP/3 QUIC module triggered by a specially crafted session when ASLR is disabled or bypassed. CVE-2026-42055 (CVSS 9.2) is a heap buffer overflow in HTTP/2 proxy modules when specific configurations combine large header buffers (greater than 2MB) with disabled invalid header checks. Both can be exploited by remote unauthenticated attackers. F5 products have been repeatedly exploited in the wild, and NGINX Rift (CVE-2026-42945, EPSS 97th percentile) came under active exploitation within days of disclosure last month.
INC Ransomware: 830 Victims Since 2023
INC ransomware has emerged as one of the most prolific cybercrime groups in 2026, claiming 830 victims since August 2023. The group became the fourth most prominent ransomware operation in Q1 2026 with over 120 incidents, trailing only Qilin (338), Akira (197), and The Gentlemen (192). INC capitalized on the disruption of LockBit and shutdown of BlackCat by recruiting migrating affiliates. Over 65% of victims are United States organizations, with legal services, manufacturing, construction, technology, and healthcare among the most targeted sectors. The operation has rewritten its Windows and Linux/ESXi encryptors in Rust for easier cross-platform development and better reverse engineering resistance. Affiliates gained initial access by exploiting CVE-2023-3519 and CVE-2025-5777 (Citrix NetScaler, both CISA KEV with EPSS 99th+ percentile), CVE-2023-48788 (Fortinet EMS, CISA KEV, EPSS 98.5th percentile), and CVE-2024-57727 (SimpleHelp, CISA KEV due March 2025, EPSS 95.1st percentile). The sale of INC's encryptor code on the underground in May 2024 spawned related families like Lynx and Sinobi with significant code overlap.
DragonForce Abuses Microsoft Teams Relays to Hide Backdoor Traffic
DragonForce ransomware operators deployed a custom Go-based RAT called Backdoor.Turn that conceals command-and-control traffic inside Microsoft Teams relay infrastructure. The backdoor was used against a major U.S. services firm, with attackers maintaining access for one to two months. Backdoor.Turn requests an anonymous Teams visitor token from Microsoft's Skype identity services, uses a legitimate Microsoft TURN relay server during connection setup, and then establishes a direct QUIC session to the attacker's C2 server. To network defenders, all visible traffic was outbound connections to legitimate Microsoft Teams servers. The attack chain began in December 2025, with initial access suspected via exploitation of an SQL or MS-SQL server vulnerability or acquisition from an initial access broker. Attackers used a DLL side-loading attack that dropped reconnaissance tools, set up persistence, and silenced security software using a Huawei driver (HWAuidoOs2Ec.sys) via BYOVD. Other drivers used in DragonForce campaigns include wsftprm.sys (CVE-2023-52271), GameDriverX64.sys (CVE-2025-61155), K7RKScan.sys (CVE-2025-1055), and ABYSSWORKER (custom driver previously seen in Medusa ransomware).
The Gentlemen Ransomware: Multiple EDR Killers in Active Development
The Gentlemen ransomware-as-a-service is actively developing and maintaining a suite of endpoint detection and response killers to help affiliates evade detection. The gang employs a custom tool dubbed GentleKiller with at least eight variants impersonating legitimate security products including Kaspersky, Valorant, Javelin, and WatchDog. Each variant uses different vulnerable drivers to achieve kernel-level privileges via BYOVD, but all share common strings, identical code obfuscation techniques, and similar process-killing logic. GentleKiller targets more than 400 processes associated with approximately 48 security vendors including Microsoft, CrowdStrike, SentinelOne, Palo Alto, Sophos, Trend Micro, ESET, Bitdefender, McAfee/Trellix, and Kaspersky. The framework is designed to allow easy driver swaps or weaponization of newly disclosed flaws without requiring major code changes. The binaries are protected by commercial Enigma and Themida packing tools. The threat group's collection also incorporates at least three external EDR killers: HexKiller (previously used by Warlock gang), ThrottleBlood (linked to MesudaLocker and DragonForce), and HavocKiller (seen in other ransomware operations). Researchers believe Gentlemen picks targets based on FortiGate endpoint configuration, particularly interesting given the recent FortiBleed leak of nearly 74,000 FortiGate VPN credentials. The gang previously compromised Romanian energy provider Oltenia and has been linked to a SystemBC proxy malware botnet with over 1,570 hosts believed to be corporate victims.
Operation Endgame Disrupts SocGholish Infrastructure
Global law enforcement announced a major disruption to TA569, the threat group behind SocGholish, as part of Operation Endgame. The Netherlands, Canada, United States, and Germany with Europol support took down over 100 servers and domains worldwide and remediated 14,971 compromised websites serving SocGholish injects. TA569 has been tracked since 2018 and is one of the most prominent cybercriminal threat groups. The group compromises websites and uses traffic direction systems to redirect visitors to malware. SocGholish web injects impersonate browser security updates to trick users into downloading malware, which often leads to follow-on ransomware attacks. Many of the compromised websites had millions of visitors, making it a prominent global threat. TA569 pioneered the web inject technique now used by numerous other threat clusters including ClearFake, ZPHP, and ErrTraffic. Attackers gain access through password spraying, leaked or reused credentials, vulnerabilities in hosting platforms, flaws in CMS core or plugins/themes, or weaknesses in third-party services. In some cases, attackers patch the original access point to prevent other threat actors from using the same vulnerability.
HCRG Care Group Notifies Patients 16 Months After Medusa Ransomware Attack
UK healthcare provider HCRG Care Group is finally notifying patients of a ransomware attack that occurred in February 2025, more than one year after the Medusa ransomware gang claimed responsibility. While HCRG confirmed the breach in February 2025, they remained silent on details. SuspectFile obtained and reported on data provided by Medusa, making it clear patient information was compromised.
HHS Settles with Spencer Gifts Health Plan for $450K After Ransomware Investigation
The U.S. Department of Health and Human Services Office for Civil Rights announced a settlement with Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans over potential HIPAA violations related to a ransomware attack. The settlement includes a $450,000 payment and a corrective action plan.
Klue Supply Chain Attack Hits Cybersecurity Firms
A supply chain attack on market intelligence platform Klue compromised multiple cybersecurity firms' Salesforce data. The attack began on June 11 when threat actors breached Klue's backend system and pushed a code update to harvest OAuth tokens for customer integrations. Klue notified customers on June 12 and deactivated OAuth tokens for all customers, disabling integrations with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack. Salesforce disabled the Klue Battlecards app integration on June 17. Cybersecurity vendors Huntress and Recorded Future confirmed they were impacted. The attackers authenticated through a compromised Klue integration service account, generated OAuth tokens granting access to customers' Salesforce instances, and automated Python scripts to exfiltrate data via the Salesforce REST API over 24 hours. One environment experienced a concentrated burst of nearly 1,000 queries in 15 minutes and sustained extraction windows lasting over six hours. The stolen data includes business contacts, price quotes, sales-related data and messaging. Huntress traced the breach to a long-disused but still active credential initially created for Klue to test a third-party integration that was never deployed. Huntress received attempted extortion communication from a threat actor calling itself Mr Brean, who pointed to a Session Messenger ID associated with Icarus, an extortion group that emerged in April 2026. This attack follows the same pattern as previous Salesforce, Salesloft Drift, and Gainsight incidents attributed to ShinyHunters and UNC6395.
ShapedPlugin WordPress Supply Chain Attack
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack that distributed infected releases to paying customers via the vendor's official update system. The malware installed a fake plugin impersonating WooCommerce components, steals credentials, and grants operators remote file-writing capabilities. The breach affected three paid plugins: Product Slider Pro (before 3.5.4), Real Testimonials Pro (3.2.5), and Smart Post Show Pro (before 4.0.2). The backdoor was injected into ShapedPlugin's Pro builds on May 21, with first customer reports emerging on June 10. Researchers confirmed the breach after downloading infected plugins from the ShapedPlugin site on June 12, and the publisher acknowledged the incident on June 16. The infected plugins contain a malicious loader file (LicenseLoader.php) that activates when a WordPress administrator accesses the admin panel. It contacts the C2 server, downloads the backdoor, installs it as a fake plugin (woocommerce-subscription or woocommerce-notification), reports to the attacker, and self-deletes. The fake plugin is hidden from the WordPress plugin list and attempts to steal WordPress login credentials, 2FA secrets, database credentials, WordPress authentication keys from wp-config.php, administrator account details, SMTP/email service credentials, and WooCommerce order data from the past three months including payment method information. Researchers believe this was a build pipeline compromise based on file modifications, timestamp patterns suggesting automated injection, and Git build references in the packages. Releases hosted on WordPress.org were confirmed clean.
AutoJack: AI Agent Framework RCE via Localhost Trust Boundary
Microsoft researchers disclosed AutoJack, an exploit chain in AutoGen Studio (AutoGen's prototyping UI) that allows untrusted web content rendered by a browsing agent to reach a local Model Context Protocol WebSocket and spawn arbitrary processes on the host. The technique leverages the localhost trust boundary that many developer tools rely on. The vulnerability was reported to MSRC and the maintainers hardened the upstream main branch. The affected MCP WebSocket surface was never included in a PyPI release, so users who install AutoGen Studio from PyPI are not exposed. The exploit chain comprises three weaknesses: origin allowlist trusts localhost but a local agent is localhost (CWE-1385), authentication middleware is opt-out for MCP paths (CWE-306), and StdioServerParams from URL is executed verbatim (CWE-78). The broader lesson is general: if an agent can browse untrusted pages and talk to privileged local services, loopback becomes an attack surface and control planes must be authenticated, authorized, and isolated.
Microsoft 365 Backup Gaps Require Third-Party Solutions
Microsoft 365 does not provide built-in protection for business data. Microsoft operates under a shared responsibility model where Microsoft ensures service availability and infrastructure security, but data protection including backup and recovery remains the customer's responsibility. Native Microsoft 365 retention policies are insufficient for compliance requirements, especially for organizations needing long-term flexible data retention. Microsoft 365 does not fully protect against ransomware and malicious data loss, particularly when encrypted or deleted files are synced across accounts. While versioning and recycle bins provide limited recovery, they are not designed to ensure clean, reliable restoration after sophisticated attacks. When files in OneDrive or SharePoint are encrypted by ransomware, changes are synchronized instantly across users and devices. Native version history may help in simple cases, but attackers frequently corrupt multiple versions or attacks remain undetected long enough to render recovery points unusable. Microsoft's tools cannot effectively identify which versions of files are safe and which are compromised.
Rockwell Automation FactoryTalk Historian Authentication Bypass
Rockwell Automation FactoryTalk Historian Site Edition 11 has an authentication bypass vulnerability (CVE-2025-13036) where continually sending requests to the login endpoint allows an attacker to obtain a valid authentication token. Additional vulnerabilities include CVE-2025-44019 and CVE-2025-36539, both uncaught exceptions that could allow authenticated users to shut down necessary PI Data Archive subsystems resulting in denial of service. Depending on crash timing, data in snapshots/write cache may be lost. Customers unable to upgrade should apply patch BF32850 and use security best practices.
Industrial Control System Vulnerabilities
CISA published multiple ICS advisories. AzeoTech DAQFactory versions 21.1 and prior have a type confusion vulnerability (CVE-2026-12390) exploitable via specially crafted .ctl files resulting in code execution. Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module has a denial-of-service vulnerability (CVE-2026-8806) when a large number of communication packets are sent in a short period. Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP Module version 1.000 and prior has an integer overflow vulnerability (CVE-2026-8805) allowing denial of service via rapid TCP connection establishment. AVer PTC cameras (PTC500S, PTC115, PTC500+, PTC115+) have improper input validation (CVE-2026-40624) allowing remote unauthenticated attackers to achieve arbitrary code execution via specially crafted web requests. Schneider Electric products have insufficient entropy vulnerability (CVE-2026-4827) in session management protections. Schneider Electric EasyLogic T150 and Saitel DP have path traversal vulnerability (CVE-2026-6865) causing unauthorized access to sensitive files.
Medical Device Bluetooth Vulnerabilities
Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT has two vulnerabilities: CVE-2026-50034 allows attackers within Bluetooth Low Energy communication range to passively intercept wireless traffic and obtain sensitive health information including glucose measurements transmitted in cleartext. CVE-2026-52866 allows attackers to monopolize the device's only available BLE connection slot, preventing legitimate users from connecting. Apollo Pharmacy did not respond to CISA's coordination requests.
Apple Beats Studio Buds Microphone Eavesdropping Flaw
Apple patched CVE-2025-20701 (CVSS 8.8), an incorrect authorization vulnerability in the Airoha Bluetooth audio SDK affecting Beats Studio Buds wireless earbuds. An attacker within Bluetooth range can listen through the microphone of a device not yet paired and actively seeking pair requests. The flaw allows pairing a Bluetooth audio device without user consent and could lead to remote escalation of privilege without requiring additional execution privileges or user interaction. The vulnerability was disclosed in June 2025 at the TROOPERS conference alongside CVE-2025-20700 and CVE-2025-20702. In most cases, these vulnerabilities allow attackers to fully take over headphones via Bluetooth without authentication or pairing. Fixed in Beats Firmware Update 1B211. Jabra released similar patches in December 2025.
Unpatchable iPhone SecureROM Exploit for A12/A13 Chips
Paradigm Shift disclosed a novel iPhone SecureROM vulnerability impacting Apple's A12 and A13 chips with proof-of-concept exploit codenamed usbliter8. The exploit leverages a hardware bug in the USB controller and a configuration flaw in device firmware. As these vulnerabilities reside in immutable code, affected users cannot patch them and should migrate to newer hardware. The exploit triggers a buffer underflow primitive in the USB controller's memory buffer, allowing malicious code injection and execution. The problem is rooted in USB controller hardware, not Apple's software. A11 chips are not susceptible. A12 and A13 USB DART is configured in bypass mode, allowing SRAM data to be overwritten freely. A14 and later generations configure DART correctly in SecureROM, making the vulnerability unexploitable.
Microsoft June 2026 Vulnerabilities
Microsoft published multiple CVEs in its June 2026 security update. CVE-2026-47633 is an information disclosure vulnerability in Cost Management exposing sensitive information to unauthorized actors over a network. CVE-2026-32208 is a cross-site scripting spoofing vulnerability in Microsoft Edge Chromium-based. CVE-2026-32174 is an improper authentication elevation of privilege vulnerability in Azure Bot Service. CVE-2026-42895 is a command injection tampering vulnerability in Microsoft Copilot allowing unauthorized attackers to perform tampering over a network. CVE-2026-47646 is a cross-site scripting spoofing vulnerability in Dynamics 365 Customer Voice. Additional third-party component CVEs published: CVE-2026-42014 (GnuTLS use-after-free), CVE-2026-48914 (QEMU-KVM heap buffer overflow), CVE-2026-53689, CVE-2026-12087 (Perl Socket out-of-bounds heap read), CVE-2026-9669 (Python bz2.BZ2Decompressor stack buffer overflow), CVE-2026-43966 (HTTP response splitting), CVE-2026-10275 (OpenSC buffer overflow), CVE-2026-44967 (OpenTelemetry unbounded HTTP response).
Windows Server 2016 Security Update Failures Fixed
Microsoft fixed a known issue causing June 2026 security updates to fail on Windows Server 2016 systems that were not up to date. The bug primarily affected customers attempting to install KB5094122 without first installing May's KB5087537 security update. Affected devices received error code 0x80070002 (ERROR_FILE_NOT_FOUND) during update installation. The issue is now resolved. Last month Microsoft resolved a similar issue causing installation failures and 0x800f0922 errors when deploying the May 2026 Windows 11 security update (KB5089549) triggered by insufficient free space on the EFI System Partition. Microsoft is also investigating an issue blocking third-party applications from launching Word, Excel, PowerPoint, Access, and other Office applications after installing June 2026 updates.
Today's intelligence reveals a pattern of sophisticated supply chain attacks targeting trusted software ecosystems. The ShapedPlugin WordPress compromise, Klue Salesforce integration attack, and SocGholish infrastructure disruption all demonstrate how attackers are moving upstream to compromise software distribution channels rather than individual targets. The FortiBleed credential exposure represents one of the largest known Fortinet compromises and underscores the continued risk of plaintext credential storage in configuration files. The rapid exploitation of Splunk Enterprise CVE-2026-20253 within days of disclosure highlights the importance of emergency patching for internet-accessible management platforms. INC ransomware's rise to become a top-tier operation demonstrates how ransomware groups capitalize on competitor disruption and Law enforcement actions create opportunities for aggressive expansion.