Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure
2026-06-25T02:51:42Z•68e3541938a110c0a2960966274ca3dab0221c0bbe3e538f68c69a56cbf01f22
ai-securityandroid-trojancisco-sd-wancordycepscredential-harvestingdifydifytapfileless-malwarefortibleedfortinethttp2-dosivantikluemacosmalicious-packagesopenclaworaclephantom-stealerrokarolla-fraudster-trojan-androids-atk-privacy-ids-unknown-2026salesforcesd-wansocgholishsupply-chaintraffic-distribution-systemszero-day
What happened
This DarkReading digest highlights an active surge in high-impact exploits, credential theft campaigns, and supply-chain/AI threats. Notable incidents include attackers exploiting a Cisco SD‑WAN flaw (used for rogue peering to gain admin/root access prior to disclosure), large-scale FortiGate/Fortinet credential-harvesting campaigns (including FortiBleed-style sniffers to collect millions of credentials), and continued Salesforce data thefts leveraging compromised third-party apps (Klue/OAuth tokens). Multiple zero-days and rapid post-disclosure exploitation were reported (Ivanti, Oracle), and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 68e3541938a110c0a2960966274ca3dab0221c0bbe3e538f68c69a56cbf01f22
- Enrichment time
- 2026-06-25T02:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.