Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attack

2026-06-21T08:51:50Z162ba4873cf956c37913d32a239995ea6ac6d0b4aa252c987b6a7f4991d0b855
Accenture-acquisitionAndroid-developer-verificationCISACVE-2026-20253DragosFortinetGitHub-abuseGoogleHAMLOCKHuntressKlueMastodonNetRiseOT-security','BlackFog','shadow-AI','macOS','Safecloud','browserRCESalesforceSplunkVirusTotalcredential-theftcrypto-malwarehardware-backdoorreCAPTCHArunZerosupply-chaintwo-factor-auth

What happened

Weekly roundup: multiple high-impact incidents and product/security updates. Most urgent: an unauthenticated remote code execution in Splunk Enterprise (CVE-2026-20253) is under active exploitation and listed by CISA, requiring immediate mitigation/patching. Other notable items: theft of ~74k Fortinet firewall credentials; a Klue-origin breach that led to Salesforce data theft affecting Huntress; a crypto‑stealing malware campaign that abused GitHub, YouTube and VirusTotal to build trust for malicious tools; and academic research (HAMLOCK) demonstrating a stealthy hardware/software backdoor. R

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
162ba4873cf956c37913d32a239995ea6ac6d0b4aa252c987b6a7f4991d0b855
Enrichment time
2026-06-21T08:51:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attack · Baitaphish