SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 102
2026-06-22T02:51:49Z•388647a079ea3f2e796627e2097b2b2f68d6a9a71ac13f0cfc946394488ce5cc
active-exploitationcisaclipboard-clippercredential-leakcrypto-theftcve-2026-20253data-leakdialog-leakedr-killerfortibleedfortinetgentlekillerincident-responseknown-exploited-vulnerabilitiesoptinmonstersocgholishsplunksupply-chainwordpress
What happened
Security Affairs roundup reports multiple high-impact incidents: FortiBleed — a massive credential leak for ~74,000 Fortinet FortiGate/SSL VPN devices with active exploitation and a CISA emergency alert; Splunk Enterprise flaw CVE-2026-20253 (PostgreSQL sidecar improper authentication, CVSS 9.8) added to CISA’s Known Exploited Vulnerabilities catalog with an urgent remediation deadline; law-enforcement Operation EndGame disrupted SocGholish, taking down 106 servers and cleaning ~14,971 WordPress sites; an exposed Elasticsearch cluster revealed ~24 billion stolen credentials; Tor-based clipper/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 388647a079ea3f2e796627e2097b2b2f68d6a9a71ac13f0cfc946394488ce5cc
- Enrichment time
- 2026-06-22T02:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.