A series of reports continue to document FortiBleed—an ongoing credential-harvesting campaign focused on large numbers of internet-facing FortiGate devices. Researchers say attackers created a confirmed-credential trove on the order of tens of thousands, enabling follow-on access well beyond the initial compromise.
The key takeaway for defenders: patching alone isn’t enough if vulnerable devices remain exposed and misconfigured for prolonged periods. Organizations running perimeter Fortinet appliances should prioritize exposure reduction, validate compensating controls, and treat stolen credentials as potentially active.
Source: SecurityWeek
Squidbleed (CVE-2026-47729): decades-old Squid bug can leak credentials via memory overread
Researchers disclosed “Squidbleed,” a longstanding Squid Proxy weakness that can expose other users’ HTTP data—including credentials and session tokens—through a memory overread. The flaw is described as introduced in 1997 and remained undetected across many revisions, leaving it a persistent risk in default configurations.
For incident-ready teams, the immediate priority is identifying affected Squid deployments and evaluating mitigation paths (configuration hardening, updates where available, and limiting proxy exposure). Because the impact is cross-user data leakage, monitoring for abnormal credential usage after exposures is also critical.
Source: Security Affairs
Trump executive order accelerates post-quantum cryptography migration deadlines for U.S. agencies
The Trump administration signed executive actions requiring federal agencies to accelerate post-quantum cryptography (PQC) transition for high-value assets and high-impact systems. The move effectively tightens planning horizons for cryptographic agility, inventorying, and migration programs across government environments.
Cyber leaders should treat this as a signal to align vendor roadmaps, identify where PQC will be feasible first (e.g., TLS, code signing, VPN), and ensure procurement requirements include cryptographic transition support. Even if “harvest now, decrypt later” timelines are debated, compliance and migration execution are now accelerating.
Source: SecurityWeek
WhatsApp VBScript campaigns: messaging-driven delivery installs legitimate RMM tooling for persistent access
New analysis describes WhatsApp-based malware delivery chains using VBScript that ultimately install legitimate remote management (RMM) software. By blending into normal IT tooling behavior, these campaigns can complicate detection and help attackers maintain long-term footholds.
Defenders should focus on blocking the initial lure vectors (malicious documents/links), monitoring for RMM installation and first-time usage patterns, and using allowlisting/command-control visibility to catch “legit-but-abused” tooling. With social messaging as the front door, endpoint controls and user-response training become even more operationally important.
Source: Kaspersky Blog
OpenAI expands Daybreak to improve vulnerability discovery and push faster remediation
OpenAI’s Daybreak initiative is expanding efforts that combine AI models, security workflows, and partnerships intended to help organizations discover and fix vulnerabilities more effectively. Coverage emphasizes shifting from “finding bugs” toward accelerating remediation bottlenecks with security-focused models and operational support.
For security teams evaluating AI assistance, the practical lens is workflow integration: how quickly findings can be validated, translated into patches, and tracked through change management. Expect more scrutiny on governance, provenance of fixes, and how organizations measure “time-to-remediate” rather than model accuracy alone.
Source: Help Net Security
Cloud and enterprise security reality check: Zero Trust fails when policy drifts out of operational sync
A Check Point analysis argues that Zero Trust plans often break down during day-to-day operations—when access rules become stale, legacy controls persist, and temporary permissions never get revisited. The result is a policy layer that changes faster than teams can validate it, undermining least privilege and segmentation goals.
The actionable message is operational: treat policy like production code—version it, review it continuously, and connect it to ownership so stale rules can be retired. As cloud migration and contractors expand, “who owns the access decision?” becomes as important as “what does the policy say?”
Source: Check Point Blog
You May Also Be Interested In...
Anthropic’s Mythos AI claims spark shutdown order and scrutiny
Xsolis data breach affects 1.4 million individuals
GTA 6 early access scams target fans with fake offers