A widespread credential-dumping incident, dubbed FortiBleed, reportedly exposed configuration artifacts for nearly 74,000 Fortinet devices, including usernames, email addresses, and plaintext admin passwords. NCSC UK also issued guidance after observing global targeting of Fortinet firewalls and VPN gateways, underscoring how quickly stolen credentials translate into real compromise attempts. The practical takeaway: treat exposed credentials as an active threat, rotate immediately, and verify remote administration paths are properly restricted and monitored.
Source: Help Net Security
Microsoft RoguePlanet: Defender zero-day (CVE-2026-50656) under active patching
Microsoft confirmed RoguePlanet, a Defender-related privilege escalation issue tracked as CVE-2026-50656, and said a fix is under development. The flaw is described as a race condition that can allow attackers to elevate privileges to the highest level through the Microsoft Malware Protection Engine. Organizations using Microsoft Defender should prioritize internal risk review, watch for mitigations/workarounds from Microsoft, and ensure detection controls are tuned for related suspicious behavior.
Source: Malwarebytes Blog
F5 issues out-of-band patches for critical NGINX bugs enabling remote, unauthenticated impact
F5 released urgent patches for two critical NGINX flaws that could allow remote unauthenticated attackers to trigger memory corruption and potentially achieve denial of service or code execution. Because these are described as exploitable without authentication, defenders should assume scanning attempts may follow quickly after disclosure. Patch cadence matters: prioritize affected NGINX deployments, validate version numbers, and confirm compensating controls (WAF/allowlists/rate limits) are in place while updates roll out.
Source: SecurityWeek
Operation Endgame: SocGholish infrastructure disrupted; nearly 15,000 WordPress sites cleaned
International law enforcement action under Operation Endgame took down 106 SocGholish servers/domains and helped remediate nearly 15,000 compromised websites that were used to deliver fake software updates. The takedown targets an infection chain that historically provides initial access for downstream criminal activity. While the disruption is significant, defenders should treat it as a reminder to verify web and update mechanisms are hardened, integrity-checked, and that legacy persistence indicators are actively hunted.
Source: Help Net Security
Ransomware crew “Gentlemen” maintains EDR-killer tooling across 48 products / 400+ processes
ESET’s investigation describes “Gentlemen” as maintaining a framework of EDR-killing tools supplied directly to ransomware affiliates. Rather than relying on affiliate-side improvisation, the operators develop and distribute repeatable disablement tooling, increasing the reliability of hostile outcomes. For incident response and hardening, this elevates the importance of tamper protection, allowlisting, recovery-tested backups, and visibility into endpoint security process manipulation.
Source: ESET Blog
AI exfiltration and privilege escalation via “trust boundary” failures in enterprise tools (Copilot + LiteLLM)
Research highlighted multiple enterprise AI breakages driven less by novel malware and more by broken trust boundaries—where URLs, agent tooling, and gateway components effectively become exfiltration or privilege-escalation paths. Examples include an issue in Microsoft 365 Copilot Enterprise Search enabling mailbox search and data exfiltration via indirect flows, and separate findings showing LiteLLM gateway authorization weaknesses that could expose provider credentials. The key operational lesson is governance-by-design: inventory AI tools and gateways, enforce least privilege, restrict network egress paths, and verify vendor fixes/configuration rather than assuming “approved” interfaces are safe.
Source: VentureBeat
You May Also Be Interested In...
eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address (Fri, Jun 19th)
Popa Botnet Linked to Publicly-Traded Israeli Firm
Companies are discarding the logs they need to catch a breach