Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure

2026-06-25T02:51:42Z68e3541938a110c0a2960966274ca3dab0221c0bbe3e538f68c69a56cbf01f22
ai-securityandroid-trojancisco-sd-wancordycepscredential-harvestingdifydifytapfileless-malwarefortibleedfortinethttp2-dosivantikluemacosmalicious-packagesopenclaworaclephantom-stealerrokarolla-fraudster-trojan-androids-atk-privacy-ids-unknown-2026salesforcesd-wansocgholishsupply-chaintraffic-distribution-systemszero-day

What happened

This DarkReading digest highlights an active surge in high-impact exploits, credential theft campaigns, and supply-chain/AI threats. Notable incidents include attackers exploiting a Cisco SD‑WAN flaw (used for rogue peering to gain admin/root access prior to disclosure), large-scale FortiGate/Fortinet credential-harvesting campaigns (including FortiBleed-style sniffers to collect millions of credentials), and continued Salesforce data thefts leveraging compromised third-party apps (Klue/OAuth tokens). Multiple zero-days and rapid post-disclosure exploitation were reported (Ivanti, Oracle), and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
68e3541938a110c0a2960966274ca3dab0221c0bbe3e538f68c69a56cbf01f22
Enrichment time
2026-06-25T02:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.