'Djinn' Stealer Targets Cloud, AI Credentials
2026-06-30T02:51:42Z•e2af825b4b51c33063aa7cc90dc0e7237dfd6bf9a43deeba34a0742eda80f96b
AI-credentialsCI/CD-malicious-PRsCVE-2026-48558Cisco-CUCMCisco-SD-WANDifyTapFortiGateOAuth-token-theftSSRFauthentication-bypasscloud-credentialscredential-harvestinfostealermalicious-packagessupply-chainthird-party-risk
What happened
The feed highlights a surge in credential-theft and supply-chain attacks that threaten cloud, AI, and enterprise systems. Key incidents include the 'Djinn' infostealer delivered via a critical SimpleHelp authentication-bypass (CVE-2026-48558) to harvest cloud and AI credentials; an Amazon Q VS extension flaw enabling arbitrary code execution and cloud credential theft; a massive FortiGate credential-harvesting campaign (FortiBleed) affecting hundreds of thousands of devices; rapid exploitation of Cisco CUCM (SSRF -> root) and SD‑WAN flaws for admin/root access; DifyTap vulnerabilities allowing
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- e2af825b4b51c33063aa7cc90dc0e7237dfd6bf9a43deeba34a0742eda80f96b
- Enrichment time
- 2026-06-30T02:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.