Squidbleed: 29-Year-Old Squid Bug Leaks User Credentials

2026-06-23T08:51:48Z22dd8804e3150e2f795358426753caa151a80b216958b21821c48193b5891aa9
CVE-2026-47729a12a13ai-security-incidentanthropicarystingerbootromcredential-harvestingcredentialsdata-breachfortibleedfortigatemalwarememory-overreadmythosransomware-prepremote-accessrouterssquid-proxysquidbleedthird-party-vendortpwdunpatchable-exploitusbliter8whatsapp

What happened

Feed of security headlines (Jun 22–23, 2026) covering multiple high-impact incidents: Squidbleed (CVE-2026-47729), a 29-year-old Squid Proxy memory overread that can leak credentials and HTTP tokens; FortiBleed, a large credential-harvesting campaign impacting 430k+ FortiGate devices and yielding ~110M credentials; a Texas Parks & Wildlife third‑party vendor breach exposing ~3M people's data; a WhatsApp-based malware campaign that hijacks accounts and installs legitimate remote-admin tools; AryStinger compromising 4,300+ outdated routers to build stealthy spy infrastructure; usbliter8, an un‑p

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
22dd8804e3150e2f795358426753caa151a80b216958b21821c48193b5891aa9
Enrichment time
2026-06-23T08:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.