The FortiBleed credential-harvesting campaign targeted internet-accessible Fortinet FortiGate firewalls and SSL VPN gateways, exposing authentication secrets from approximately 74,000 devices globally. Custom sniffers were deployed on compromised devices to extract credentials directly from network traffic. CISA issued updated guidance referencing PBKDF2 credential storage, mandatory session termination, and password resets for affected organisations.
Squidbleed (CVE-2026-47729) is a heap out-of-bounds read vulnerability in Squid's FTP gateway that can expose one user's cleartext HTTP requests, including credentials and session tokens, to another user of the same proxy. The flaw traces to FTP parsing code introduced in 1997 and remains present in Squid's default configuration. Proof-of-concept code is publicly available, with fixes released in the 7.x branch.
Law enforcement disrupted the SocGholish malware delivery operation under Operation Endgame, remediating thousands of compromised websites used by TA569 for initial access. Separately, CSIS in Canada used a first-of-its-kind threat reduction warrant to neutralise two foreign-run botnets by directly accessing infected routers and servers on Canadian soil. The AryStinger botnet infected at least 4,300 end-of-life D-Link DIR-850L and DIR-818LW routers, exploiting vulnerabilities disclosed 13 years ago to build a distributed reconnaissance and proxy network.
The Klue business intelligence platform was breached via Salesforce OAuth token theft by a group identified as Icarus, compromising data from hundreds of customers. Named affected organisations include HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium. North Korean threat actor Sapphire Sleet conducted a separate supply chain attack against over 140 Mastra NPM packages, injecting a malicious dependency that fetches payloads targeting cryptocurrency wallet extensions.
Hola Browser for Windows version 1.251.91.0 was compromised in a supply chain attack that distributed a Monero cryptocurrency miner via the vendor's software distribution pipeline. The malware added persistence as HolaMonitorService.exe, excluded itself from Microsoft Defender, and activated mining during device idle periods. A ShapedPlugin WordPress plugin supply chain attack similarly backdoored multiple Pro plugin releases by compromising the vendor's build and distribution pipeline.
Brazil's Civil Defense Alert system was compromised in a suspected cyberattack, pushing unauthorised "extreme" alerts reading "Alerta extremo - Defesa Civil:misantropi4" to devices across São Paulo, Rio de Janeiro, Paraná, and the Federal District. The dispatch platform was taken offline and investigations are ongoing by SEDEC and the Federal Police. Gizmodo's website was separately compromised, delivering ClickFix malware prompts attributed to an ErrTraffic affiliate, with the Windows payload deploying NetSupport RAT.
CISA reported that malicious cyber actors targeted internet-accessible Fortinet devices across government and private-sector organisations using compromised credentials in activity tracked as FortiBleed. The agency said leaked credentials were associated with approximately 74,000 Fortinet devices, including FortiGate firewalls and SSL VPN gateways exposed to the internet. Updated guidance references Fortinet recommendations on PBKDF2 credential storage, session termination and password resets following reports of credential exposure affecting globally deployed systems.
Researchers disclosed SquidBleed, tracked as CVE-2026-47729, a heap out-of-bounds read vulnerability in Squid's FTP gateway that can expose another user's cleartext HTTP requests, including credentials and session tokens. The flaw originates from FTP parsing code introduced in 1997 and can be exploited by a trusted proxy user through a malicious FTP server, causing Squid to return data from unrelated transactions stored in reused memory buffers. Squid maintainers released fixes in the 7.x branch and described the issue as an out-of-bounds read affecting the FTP gateway, while proof-of-concept code is publicly available and no in-the-wild exploitation has been reported.
Hola confirmed a supply chain attack after researchers found that Hola Browser for Windows version 1[.]251[.]91[.]0 was distributing an unauthorised executable that installed a Monero cryptocurrency miner on affected systems. The malware, saved as me.exe, added its own files to Microsoft Defender exclusions, created the persistent HolaMonitorService.exe process and hola_monitor_svc service, and activated mining activity when the device was idle. Hola said the incident affected approximately 0.1% of users and was linked to a compromise in its software distribution pipeline.
Cloudflare engineers identified a timing-dependent race condition in the Rust hyper HTTP/1 library that caused large image responses to be truncated when socket backpressure delayed buffer flushing before shutdown. The issue surfaced after a rearchitecture of Cloudflare’s Images binding introduced a faster local intermediary, exposing a condition where hyper discarded a pending flush result and prematurely issued SHUT_WR while megabytes of response data remained buffered. The bug was reproduced under production-like concurrency using strace and confirmed across hyper versions, with a fix applied by ensuring poll_flush completion before socket shutdown in the dispatch lifecycle.
Researchers identified a bucket hijacking technique exploiting globally unique cloud storage bucket names, where attackers delete a target bucket and recreate it under their own account to intercept ongoing data streams. The method affects multiple cloud services including Google Cloud Logging, Pub/Sub, Storage Transfer Service, AWS S3 replication and Amazon Data Firehose, allowing redirected logs, messages and objects into attacker-controlled storage. No active real-world exploitation has been observed, but simulations confirmed feasibility when attackers have permissions to delete storage buckets or related routing resources.
Klue reported a breach in which attackers used a compromised legacy credential tied to an integration tool to access customer-linked cloud systems and exfiltrate data. The cybercrime group Icarus claimed responsibility and threatened to publish stolen data, with several customers including cybersecurity firms confirming impact across their environments. Stolen information reportedly included business contact data from systems such as Salesforce, and Klue engaged CrowdStrike while disconnecting integrations to contain further access.