SocGholish Takedown Highlights Malicious TDS Threats

2026-06-23T14:51:44Zbdb7cfed6a56d30b25f22505f5d67505c349ce5b4e25620a76664fea8c61c121
ai-privacycopilot-searchleakcredential-harvestingdifytapfortibleedfortigatefortinethttp2-dosivantimalwaremiasmanovo-nordiskoracle-zero-daypatchingphantom-stealerphishingransomwarerokorollasecrets-managementsocgholishsprysockssupply-chaintdszero-day

What happened

Multiple active, large-scale campaigns and high-impact vulnerabilities were reported across networking, AI, and supply-chain ecosystems. Notably, a Golang-based ‘FortiBleed’ sniffing campaign is targeting FortiGate devices at scale (reports cite ~430,000 devices scanned and ~110 million credentials identified) alongside related credential-harvesting compromises of 30K+ Fortinet devices; several zero-day/rapidly-exploited flaws were disclosed (Oracle ERP zero-day abused by ShinyHunters, Ivanti Sentry exploited within 24 hours of disclosure, Microsoft Exchange spoofing 'Ghost‑Sender'), and fourD

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
bdb7cfed6a56d30b25f22505f5d67505c349ce5b4e25620a76664fea8c61c121
Enrichment time
2026-06-23T14:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.