Security Affairs newsletter Round 582 by Pierluigi Paganini – INTERNATIONAL EDITION

2026-06-21T20:51:44Zd712276e22c4fa567ce355d786dd172882ba22d5cb14feaca323a0213465184d
24-billion-recordsCISACVE-2026-20181CVE-2026-20253Cisco ISEEDR-killerElasticsearchEuropolFortiBleedFortinetGentleKillerKEVKnown-Exploited-VulnerabilitiesSocGholishSplunkThe Gentlemenclipper-malwarecredential-sprayingcrypto-theftdata-breachransomwaretakedown

What happened

Security Affairs Round 582 highlights multiple high-impact incidents: ESET analysis of “The Gentlemen” group and its GentleKiller EDR‑killer toolkit used to disable security tools ahead of ransomware; the FortiBleed credential leak and industrial-scale credential‑spraying campaign (≈74,000 Fortinet devices) with active exploitation and a CISA emergency alert; a global takedown of the SocGholish infrastructure that cleaned ~14,971 WordPress sites; an exposed Elasticsearch cluster containing ~24 billion stolen credentials; a Tor‑based clipper campaign targeting crypto wallet seed phrases; and 2

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
d712276e22c4fa567ce355d786dd172882ba22d5cb14feaca323a0213465184d
Enrichment time
2026-06-21T20:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.