THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

4 min read

AI-assisted briefingHow we put it together ↗
FortiBleed: leaked credentials and credential-spraying at internet scale

Researchers and CISA say a large credential theft campaign targeting Fortinet FortiGate SSL VPNs (FortiBleed) resulted in tens of thousands of leaked device credentials and active attempts to use them. The campaign’s “factory” nature—mass, automated login attempts—highlights how quickly stolen access can be converted into compromise attempts across the internet. Key takeaway: treat exposed VPN credentials as an incident in themselves—assume attackers are testing immediately and prioritize credential rotation plus device verification, not just patching.

Source: Security Affairs


CISA adds Splunk Enterprise RCE to KEV: CVE-2026-20253 under active attack

CISA has added CVE-2026-20253 to its Known Exploited Vulnerabilities (KEV) catalog after confirming in-the-wild exploitation risk for Splunk Enterprise. The issue is an improper authentication vulnerability involving a PostgreSQL sidecar service, with reporting that exploitation could enable full system compromise. For defenders, the focus should be rapid patching and verification of whether systems show indicators of compromise, as KEV deadlines can compress response windows dramatically.

Source: Help Net Security


AI agent security breaks through “normal AppSec”: Langflow and LangGraph chains to RCE

New reporting underscores that common web-app bug classes—path traversal, SQL injection, unsafe deserialization—can become remote code execution when embedded inside popular AI agent frameworks. The most urgent angle is that Langflow instances (not just code) are reachable and can be exploited via unauthenticated file-write behavior, including in default configurations with auto-login. The broader lesson for enterprises: inventory and patch AI tooling like production software, treat framework dependencies as security-critical, and update governance so “shadow AI” can’t bypass controls.

Source: VentureBeat


SocGholish disrupted: law enforcement cleans 14,971 WordPress sites used in fake-update scams

An international operation disrupted infrastructure tied to the SocGholish malware network, including cleanup of nearly 15,000 compromised WordPress sites that were used to push fake browser update malware. The operation reportedly took down servers and coordinated across multiple jurisdictions through Europol, reflecting how persistent drive-by and “update” scam ecosystems rely on broad, distributed hosting. For organizations, this is another reminder to harden website supply chains (plugins/themes), monitor for unauthorized changes, and treat “compromised sites” as both an endpoint and a brand-reputation risk.

Source: Security Affairs


Klue supply-chain incident spreads: OAuth/integration abuse leads to Salesforce data theft

Multiple security firms report that they were affected by a breach that originated from Klue, a market intelligence platform that integrates CRM and sales data. The incident’s “domino” effect—starting from a compromised integration credential and cascading into Salesforce-related data access—illustrates how business tooling integrations can expand blast radius beyond the initial system. Actionable takeaway: review third-party integrations with strong access boundaries, monitor OAuth/token activity, and verify data flows across connected platforms when an integration vendor is breached.

Source: Help Net Security


Nearly 15,000 websites cleaned in SocGholish crackdown: fake update delivery remains a top distribution vector

Separate coverage emphasizes the scale and operational focus of SocGholish disruption—hundreds of malicious nodes were removed and infected WordPress sites were cleaned as part of a coordinated week of action. Fake browser update scams remain effective because they blend into user browsing behavior and often reuse familiar branding cues. Defenders should strengthen controls around content integrity (web file integrity monitoring, plugin change alerts) and improve takedown/cleanup readiness to reduce the window where compromised sites continue serving malware.

Source: MalwareBytes Blog


Apple patches Beats Studio Buds Bluetooth flaw that could turn earbuds into a “wiretap”

Apple addressed a Bluetooth vulnerability affecting Beats Studio Buds that could allow nearby attackers to listen through the earbuds’ microphone. The risk model here is physical proximity plus wireless exposure—different from typical remote server exploitation, but still highly impactful for consumer privacy. For security teams and device managers, the key point is to ensure firmware and device update workflows are tracked and that endpoint privacy threats are considered part of the broader attack surface.

Source: MalwareBytes Blog


You May Also Be Interested In... Google sets timeline for Android developer verification enforcement Mastodon 4.6 adds profile Collections and two-factor controls Cloudflare rolls out Temporary Accounts for AI agents on Workers
Cybersecurity — June 20, 2026 | Briefing24