SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 102

2026-06-22T02:51:49Z388647a079ea3f2e796627e2097b2b2f68d6a9a71ac13f0cfc946394488ce5cc
active-exploitationcisaclipboard-clippercredential-leakcrypto-theftcve-2026-20253data-leakdialog-leakedr-killerfortibleedfortinetgentlekillerincident-responseknown-exploited-vulnerabilitiesoptinmonstersocgholishsplunksupply-chainwordpress

What happened

Security Affairs roundup reports multiple high-impact incidents: FortiBleed — a massive credential leak for ~74,000 Fortinet FortiGate/SSL VPN devices with active exploitation and a CISA emergency alert; Splunk Enterprise flaw CVE-2026-20253 (PostgreSQL sidecar improper authentication, CVSS 9.8) added to CISA’s Known Exploited Vulnerabilities catalog with an urgent remediation deadline; law-enforcement Operation EndGame disrupted SocGholish, taking down 106 servers and cleaning ~14,971 WordPress sites; an exposed Elasticsearch cluster revealed ~24 billion stolen credentials; Tor-based clipper/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
388647a079ea3f2e796627e2097b2b2f68d6a9a71ac13f0cfc946394488ce5cc
Enrichment time
2026-06-22T02:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.