SocGholish Takedown Highlights Malicious TDS Threats
2026-06-23T14:51:44Z•bdb7cfed6a56d30b25f22505f5d67505c349ce5b4e25620a76664fea8c61c121
ai-privacycopilot-searchleakcredential-harvestingdifytapfortibleedfortigatefortinethttp2-dosivantimalwaremiasmanovo-nordiskoracle-zero-daypatchingphantom-stealerphishingransomwarerokorollasecrets-managementsocgholishsprysockssupply-chaintdszero-day
What happened
Multiple active, large-scale campaigns and high-impact vulnerabilities were reported across networking, AI, and supply-chain ecosystems. Notably, a Golang-based ‘FortiBleed’ sniffing campaign is targeting FortiGate devices at scale (reports cite ~430,000 devices scanned and ~110 million credentials identified) alongside related credential-harvesting compromises of 30K+ Fortinet devices; several zero-day/rapidly-exploited flaws were disclosed (Oracle ERP zero-day abused by ShinyHunters, Ivanti Sentry exploited within 24 hours of disclosure, Microsoft Exchange spoofing 'Ghost‑Sender'), and fourD
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- bdb7cfed6a56d30b25f22505f5d67505c349ce5b4e25620a76664fea8c61c121
- Enrichment time
- 2026-06-23T14:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.