CISA warns Fortinet users to secure devices after FortiBleed leak

2026-06-19T07:23:29Zc11c97e3ef4d9424e8d0066144000c289180829798e00529a3e318ac5c278545
Beats Studio BudsBluetooth vulnerabilityCISAEDR evasionEvil CorpF5FortiBleedFortinetGentlemen RaaSIcarusKlueMicrosoftNGINXOAuthShapedPluginSocGholishUSB wormVPN credentialsWindows ServerWordPresscrypto‑stealerout-of-band patchingprivacyransomwaresupply-chain

What happened

This collection of security news highlights a major Fortinet credential leak dubbed “FortiBleed” — roughly 73–74K FortiGate/VPN credentials exposed — prompting a CISA advisory urging customers to secure and remediate affected devices. Other notable stories include the Gentlemen RaaS group adding multiple EDR-killers to evade defenses, a Klue OAuth breach linked to ‘Icarus’ Salesforce data-theft attacks, a TinyPulse survey-data theft affecting Nintendo, a USB-worm distributing crypto‑stealers via Windows shortcut files, and a ShapedPlugin supply‑chain compromise that pushed infected WordPress插件

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
c11c97e3ef4d9424e8d0066144000c289180829798e00529a3e318ac5c278545
Enrichment time
2026-06-19T07:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.