Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attack
2026-06-21T08:51:50Z•162ba4873cf956c37913d32a239995ea6ac6d0b4aa252c987b6a7f4991d0b855
Accenture-acquisitionAndroid-developer-verificationCISACVE-2026-20253DragosFortinetGitHub-abuseGoogleHAMLOCKHuntressKlueMastodonNetRiseOT-security','BlackFog','shadow-AI','macOS','Safecloud','browserRCESalesforceSplunkVirusTotalcredential-theftcrypto-malwarehardware-backdoorreCAPTCHArunZerosupply-chaintwo-factor-auth
What happened
Weekly roundup: multiple high-impact incidents and product/security updates. Most urgent: an unauthenticated remote code execution in Splunk Enterprise (CVE-2026-20253) is under active exploitation and listed by CISA, requiring immediate mitigation/patching. Other notable items: theft of ~74k Fortinet firewall credentials; a Klue-origin breach that led to Salesforce data theft affecting Huntress; a crypto‑stealing malware campaign that abused GitHub, YouTube and VirusTotal to build trust for malicious tools; and academic research (HAMLOCK) demonstrating a stealthy hardware/software backdoor. R
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 162ba4873cf956c37913d32a239995ea6ac6d0b4aa252c987b6a7f4991d0b855
- Enrichment time
- 2026-06-21T08:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.