Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (20 June 2026)
Published: Loading…
At a Glance
- CVE-2026-20253 in Splunk Enterprise enables unauthenticated remote code execution and is under active in-the-wild exploitation.
- Operation Endgame disrupted 106 SocGholish servers and remediated nearly 15,000 compromised WordPress sites linked to Evil Corp.
- FortiBleed exposed credentials from approximately 86,644 Fortinet FortiGate devices in a campaign attributed to Russian-speaking threat actors.
- Fifteen malicious JetBrains Marketplace plugins exfiltrated AI API keys from roughly 70,000 developer installations over eight months.
- Klue's OAuth token breach allowed attackers to access connected Salesforce environments of customers including Huntress and Recorded Future.
- An unpatchable BootROM exploit dubbed usbliter8 breaks the secure boot chain on Apple A12 and A13 chips permanently.
Summary
CVE-2026-20253 in Splunk Enterprise enables unauthenticated arbitrary file creation and truncation via an unauthenticated PostgreSQL sidecar endpoint. Active in-the-wild exploitation was confirmed by Splunk on June 18, with proof-of-concept remote code execution code published shortly after disclosure. CISA added the flaw to its Known Exploited Vulnerabilities catalogue and ordered federal civilian agencies to apply mitigations by June 21.
Operation Endgame dismantled the SocGholish malware infrastructure in a joint action involving Dutch, Canadian, German, and US law enforcement. Authorities took down 106 command-and-control servers and domains and remediated nearly 15,000 compromised WordPress sites used to distribute fake browser updates. The operation also uncovered approximately 1.4 million leaked website credentials linked to the network, which has long provided initial access for Evil Corp ransomware deployments.
The FortiBleed campaign exposed credentials from approximately 86,644 internet-accessible Fortinet FortiGate firewalls and VPNs. An analysis of an exposed attacker server revealed tooling for internet-wide scanning, GPU-accelerated hash cracking via Hashtopolis, and Active Directory enumeration, with access logs prepared for sale. CISA urged Fortinet customers to secure devices and attributed the campaign to Russian-speaking threat actors.
Fifteen malicious plugins on the JetBrains Marketplace exfiltrated AI API keys from roughly 70,000 developer installations over an eight-month supply chain attack. The plugins impersonated AI coding assistants and transmitted captured OpenAI, DeepSeek, and SiliconFlow keys to a hardcoded server over unencrypted HTTP. JetBrains removed the plugins on June 17 and activated a remote kill-switch to disable affected extensions.
A breach at market intelligence platform Klue allowed attackers to steal OAuth tokens via a compromised legacy integration credential, enabling access to connected Salesforce environments. Cybersecurity firms Huntress and Recorded Future were among confirmed victims, with the "Icarus" extortion group publicly claiming responsibility. Salesforce disabled the Klue Battlecards app integration in response.
A new usbliter8 BootROM exploit permanently breaks the secure boot chain on Apple A12 and A13 chips, affecting iPhone XS, XR, 11, and 11 Pro models. The flaw resides in immutable SecureROM code and cannot be patched via software update. Separately, OXLOADER, a previously undocumented Windows loader distributed via malicious Google Ads, was identified delivering the CASTLESTEALER infostealer with geographic exclusions targeting CIS regions, suggesting a Russian-speaking financially motivated operator.
Highlights of the Day
Exposed Server Reveals FortiBleed Credential Theft Operation
CloudSEK analysed an exposed attacker server used in the FortiBleed campaign and found tooling for internet-wide scanning, credential harvesting, Hashtopolis-managed GPU hash cracking, Active Directory enumeration, and revenue-ranked VPN and SSH access prepared for sale. The investigation found the widely reported 21,632 figure represented FortiGuard email attribution entries rather than confirmed breaches, with evidence of captured Kerberos traffic for about 918 organisations and verified Active Directory credential compromise in approximately 148 cases, while the exposed infrastructure included rented Vast.ai GPU workers, Telegram-controlled automation, and at least one live victim SSL VPN configuration.
Operation Endgame Disrupts SocGholish WordPress Infrastructure
An international Operation Endgame action involving law enforcement and private-sector partners disrupted the SocGholish malware ecosystem by taking down 106 servers and domains and remediating 14,971 compromised WordPress sites used to distribute fake browser updates. SocGholish, also tracked as TA569, Mustard Tempest and UNC1543, uses compromised WordPress sites, traffic distribution systems, domain shadowing and fake update lures to deliver JScript payloads that provide initial access for cybercriminals including Evil Corp, with Operation Endgame also identifying approximately 1.4 million leaked website credentials that could facilitate further compromises.
Klue Breach Exposes OAuth Tokens via Legacy Credential
Klue reported on June 12 attackers used a compromised legacy integration credential to obtain OAuth tokens for Salesforce and third-party platforms, accessing connected customer environments. Klue revoked affected credentials and tokens, removed unauthorised code, disabled integrations, engaged CrowdStrike, notified law enforcement, and found no evidence of Klue platform data compromise.
Splunk Enterprise Flaw Enables Unauthenticated File Operations
Splunk disclosed CVE-2026-20253 affecting Splunk Enterprise versions 10.2 before 10.2.4 and 10.0 before 10.0.7, where a PostgreSQL sidecar service endpoint lacks authentication controls allowing unauthenticated users to perform arbitrary file creation or truncation. Cisco-owned Splunk confirmed limited in-the-wild exploitation on June 18, while WatchTowr published proof-of-concept code demonstrating remote code execution shortly after disclosure and CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue.
OXLOADER Loader Spreads CASTLESTEALER via Malvertising Campaign
Elastic Security Labs identified OXLOADER, a previously undocumented Windows loader distributed through malicious Google Ads impersonating Node.js and other tools, which delivers the CASTLESTEALER infostealer via multi-stage infection chains. The loader abuses Windows .reloc sections for shellcode staging, uses self-modifying XOR-based decryption routines, and employs control-flow flattening, opaque predicates, and mixed Boolean-Arithmetic to evade static analysis and reverse engineering tools. Execution begins via a compromised download chain involving Storj-hosted batch scripts and PowerShell-initiated payloads that trigger User Account Control elevation and deploy the loader. Anti-analysis checks include CPU, RAM, display refresh rate, and geographic filtering that excludes CIS regions and Russian-language systems before final payload execution.
Malicious JetBrains Plugins Steal AI API Keys from 70,000 Developers
Fifteen malicious JetBrains Marketplace plugins distributed under seven vendor accounts were found exfiltrating AI API keys to a hardcoded command-and-control server at 39[.]107[.]60[.]51 over unencrypted HTTP, affecting approximately 70,000 installations. The plugins impersonated AI-powered developer tools such as code review and commit generation assistants, capturing OpenAI-format keys via a save() function and transmitting them through a Java-based HTTP POST mechanism using a static authentication header. JetBrains removed the plugins on June 17, 2026, banned the associated publisher accounts, and activated a remote kill-switch that disabled the extensions while confirming no compromise of internal systems or source code.
USB BootROM Flaw Enables DFU Compromise on A12–A13 Devices
Researchers disclosed a USB controller DMA buffer underflow in Apple DWC2-based BootROM affecting A12, S4/S5, and A13 devices enabling SecureROM compromise. The exploit leverages USB Setup packet handling flaws in Synopsys DWC2 DMA behaviour, enabling buffer underflow writes into SRAM and stack corruption paths. Post-exploitation steps achieve SecureROM code execution, escalate to EL1 via SVC transitions, and enable DFU-level control for boot chain modification and iBoot loading.
Daily Coverage