CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (23 June 2026)

Published: Loading…

At a Glance

  • FortiBleed credential-harvesting campaign exposed authentication secrets from approximately 74,000 internet-accessible Fortinet FortiGate and SSL VPN devices.
  • Operation Endgame disrupted SocGholish infrastructure, remediating thousands of compromised websites operated by TA569 as an initial access service.
  • North Korean threat actor Sapphire Sleet conducted a supply chain attack against Mastra NPM packages, targeting cryptocurrency extensions across 140-plus packages.
  • AryStinger malware infected at least 4,300 end-of-life D-Link routers to build a distributed reconnaissance and proxy network.
  • Squidbleed, tracked as CVE-2026-47729, is a 29-year-old heap out-of-bounds read flaw in Squid proxy that leaks cleartext HTTP requests including credentials.
  • Klue breach via Salesforce OAuth tokens compromised data from hundreds of customers, including multiple named cybersecurity firms.

Summary

The FortiBleed credential-harvesting campaign targeted internet-accessible Fortinet FortiGate firewalls and SSL VPN gateways, exposing authentication secrets from approximately 74,000 devices globally. Custom sniffers were deployed on compromised devices to extract credentials directly from network traffic. CISA issued updated guidance referencing PBKDF2 credential storage, mandatory session termination, and password resets for affected organisations.

Squidbleed (CVE-2026-47729) is a heap out-of-bounds read vulnerability in Squid's FTP gateway that can expose one user's cleartext HTTP requests, including credentials and session tokens, to another user of the same proxy. The flaw traces to FTP parsing code introduced in 1997 and remains present in Squid's default configuration. Proof-of-concept code is publicly available, with fixes released in the 7.x branch.

Law enforcement disrupted the SocGholish malware delivery operation under Operation Endgame, remediating thousands of compromised websites used by TA569 for initial access. Separately, CSIS in Canada used a first-of-its-kind threat reduction warrant to neutralise two foreign-run botnets by directly accessing infected routers and servers on Canadian soil. The AryStinger botnet infected at least 4,300 end-of-life D-Link DIR-850L and DIR-818LW routers, exploiting vulnerabilities disclosed 13 years ago to build a distributed reconnaissance and proxy network.

The Klue business intelligence platform was breached via Salesforce OAuth token theft by a group identified as Icarus, compromising data from hundreds of customers. Named affected organisations include HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium. North Korean threat actor Sapphire Sleet conducted a separate supply chain attack against over 140 Mastra NPM packages, injecting a malicious dependency that fetches payloads targeting cryptocurrency wallet extensions.

Hola Browser for Windows version 1.251.91.0 was compromised in a supply chain attack that distributed a Monero cryptocurrency miner via the vendor's software distribution pipeline. The malware added persistence as HolaMonitorService.exe, excluded itself from Microsoft Defender, and activated mining during device idle periods. A ShapedPlugin WordPress plugin supply chain attack similarly backdoored multiple Pro plugin releases by compromising the vendor's build and distribution pipeline.

Brazil's Civil Defense Alert system was compromised in a suspected cyberattack, pushing unauthorised "extreme" alerts reading "Alerta extremo - Defesa Civil:misantropi4" to devices across São Paulo, Rio de Janeiro, Paraná, and the Federal District. The dispatch platform was taken offline and investigations are ongoing by SEDEC and the Federal Police. Gizmodo's website was separately compromised, delivering ClickFix malware prompts attributed to an ErrTraffic affiliate, with the Windows payload deploying NetSupport RAT.

Highlights of the Day

CISA Warns of Fortinet Credential Exposure Campaign

CISA reported that malicious cyber actors targeted internet-accessible Fortinet devices across government and private-sector organisations using compromised credentials in activity tracked as FortiBleed. The agency said leaked credentials were associated with approximately 74,000 Fortinet devices, including FortiGate firewalls and SSL VPN gateways exposed to the internet. Updated guidance references Fortinet recommendations on PBKDF2 credential storage, session termination and password resets following reports of credential exposure affecting globally deployed systems.

SquidBleed Bug Leaks HTTP Data From Shared Proxies

Researchers disclosed SquidBleed, tracked as CVE-2026-47729, a heap out-of-bounds read vulnerability in Squid's FTP gateway that can expose another user's cleartext HTTP requests, including credentials and session tokens. The flaw originates from FTP parsing code introduced in 1997 and can be exploited by a trusted proxy user through a malicious FTP server, causing Squid to return data from unrelated transactions stored in reused memory buffers. Squid maintainers released fixes in the 7.x branch and described the issue as an out-of-bounds read affecting the FTP gateway, while proof-of-concept code is publicly available and no in-the-wild exploitation has been reported.

Supply Chain Attack Plants Miner in Hola Browser

Hola confirmed a supply chain attack after researchers found that Hola Browser for Windows version 1[.]251[.]91[.]0 was distributing an unauthorised executable that installed a Monero cryptocurrency miner on affected systems. The malware, saved as me.exe, added its own files to Microsoft Defender exclusions, created the persistent HolaMonitorService.exe process and hola_monitor_svc service, and activated mining activity when the device was idle. Hola said the incident affected approximately 0.1% of users and was linked to a compromise in its software distribution pipeline.

Source: Kaspersky

Hyper Race Condition Drops Large Image Responses at Edge

Cloudflare engineers identified a timing-dependent race condition in the Rust hyper HTTP/1 library that caused large image responses to be truncated when socket backpressure delayed buffer flushing before shutdown. The issue surfaced after a rearchitecture of Cloudflare’s Images binding introduced a faster local intermediary, exposing a condition where hyper discarded a pending flush result and prematurely issued SHUT_WR while megabytes of response data remained buffered. The bug was reproduced under production-like concurrency using strace and confirmed across hyper versions, with a fix applied by ensuring poll_flush completion before socket shutdown in the dispatch lifecycle.

Cloud Bucket Hijacking Enables Cross-Account Data Exfiltration

Researchers identified a bucket hijacking technique exploiting globally unique cloud storage bucket names, where attackers delete a target bucket and recreate it under their own account to intercept ongoing data streams. The method affects multiple cloud services including Google Cloud Logging, Pub/Sub, Storage Transfer Service, AWS S3 replication and Amazon Data Firehose, allowing redirected logs, messages and objects into attacker-controlled storage. No active real-world exploitation has been observed, but simulations confirmed feasibility when attackers have permissions to delete storage buckets or related routing resources.

Klue Breach Exposes Customer Data via Compromised Credential

Klue reported a breach in which attackers used a compromised legacy credential tied to an integration tool to access customer-linked cloud systems and exfiltrate data. The cybercrime group Icarus claimed responsibility and threatened to publish stolen data, with several customers including cybersecurity firms confirming impact across their environments. Stolen information reportedly included business contact data from systems such as Salesforce, and Klue engaged CrowdStrike while disconnecting integrations to contain further access.

Source: Klue

Daily Coverage

Developments
Fortibleed CampaignSquidbleed DisclosureMastra Supply ChainKlue/Icarus Breach
Vulnerabilities
CVE-2026-47729CVE-2025-71326Avast Antivirus 25.11CVE-2026-12778Partition Assistant 10.10.0CVE-2026-12779Dynamic Disk Manager 10.10.0 (High)CVE-2026-12780Backupper 8.0
Threat Groups
TA569Mustard Tempest is an initial access broker that has operated the SocGholish distribution network since at least 2017. Mustard Tempest has partnered with Indrik Spider to provide access for the download of additional malware including LockBit, WastedLocker, and remote access tools.Sapphire SleetAPT38 is a North Korean statesponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau. Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext and Banco de Chile; some of their attacks have been destructive. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean statesponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.