Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploited
2026-06-28T14:51:53Z•a87510a5b14920f85eccc7e93616a5e44e171678d54c0895ab494baa88c8bf88
ai-identityakritescvehtml-smugglingmailplusmalwaremirage2faphishingpost-quantumransomwaresharkloadersim-swapstrikeSharksupply-chainsynologythreat-modelingvulnerabilityx401zerotier
What happened
Weekly security roundup: notable incidents and initiatives include ongoing impact from the Fortibleed campaign and exploitation of a Cisco Unified CM vulnerability; Synology released critical patches for MailPlus Server fixing three vulnerabilities (CVE-2026-13136, CVE-2026-13135, CVE-2025-15660) that can enable arbitrary file access, internal service access and DoS; Fortra identified the Mirage2FA phishing kit that uses HTML smuggling and obfuscated JavaScript to harvest Microsoft 365 credentials (bypassing MFA prompts); Kaspersky uncovered a novel SharkLoader dropper (StrikeShark) targeting
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- a87510a5b14920f85eccc7e93616a5e44e171678d54c0895ab494baa88c8bf88
- Enrichment time
- 2026-06-28T14:51:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.