Security Affairs newsletter Round 582 by Pierluigi Paganini – INTERNATIONAL EDITION
2026-06-21T20:51:44Z•d712276e22c4fa567ce355d786dd172882ba22d5cb14feaca323a0213465184d
24-billion-recordsCISACVE-2026-20181CVE-2026-20253Cisco ISEEDR-killerElasticsearchEuropolFortiBleedFortinetGentleKillerKEVKnown-Exploited-VulnerabilitiesSocGholishSplunkThe Gentlemenclipper-malwarecredential-sprayingcrypto-theftdata-breachransomwaretakedown
What happened
Security Affairs Round 582 highlights multiple high-impact incidents: ESET analysis of “The Gentlemen” group and its GentleKiller EDR‑killer toolkit used to disable security tools ahead of ransomware; the FortiBleed credential leak and industrial-scale credential‑spraying campaign (≈74,000 Fortinet devices) with active exploitation and a CISA emergency alert; a global takedown of the SocGholish infrastructure that cleaned ~14,971 WordPress sites; an exposed Elasticsearch cluster containing ~24 billion stolen credentials; a Tor‑based clipper campaign targeting crypto wallet seed phrases; and 2
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- d712276e22c4fa567ce355d786dd172882ba22d5cb14feaca323a0213465184d
- Enrichment time
- 2026-06-21T20:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.