Unpatchable BootROM Flaw Impacts Apple A12, A13 Chips

2026-06-22T14:52:42Z31b31dfc2937c5e4a902d58cff6d060c2b4698a11cb16ba512ae38d2a276d19d
A12A13AI threatsApple BootROMEvil CorpFortiBleedFortinetJetBrains marketplaceKlue breachMastraNCSC guidanceNorth KoreaOAuth tokensOperation EndgameOptinMonsterRokarolla Android trojanSapphire SleetSocGholishSprySOCKSUSB exploitWordPress plugin supply chainbackdoormalicious pluginssupply chain attackunpatchable exploit

What happened

Roundup of major cybersecurity developments: an unpatchable Apple BootROM USB exploit affecting A12/A13 devices has been disclosed; Microsoft links a Mastra AI supply‑chain attack to North Korean actor Sapphire Sleet; a Klue breach via Salesforce integration exposed OAuth tokens and impacted multiple cybersecurity firms. The NCSC issued FortiBleed guidance for Fortinet customers while Operation Endgame removed SocGholish from ~15,000 sites tied to Evil Corp. Other notable items include WordPress OptinMonster plugin backdoors on ~1.2M sites, SprySOCKS backdoor expanding to Windows, multiple Jet

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
31b31dfc2937c5e4a902d58cff6d060c2b4698a11cb16ba512ae38d2a276d19d
Enrichment time
2026-06-22T14:52:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Unpatchable BootROM Flaw Impacts Apple A12, A13 Chips · Baitaphish