Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data
2026-06-22T13:24:05Z•54c25211a8045c97e7fa97c4c713347c41542a06bf9a23e17e73b9341a06b6b1
API key leakageApple boot exploitBeats eavesdropping patchFortiBleedFortinetGCP Config ConnectorGravity SMTPHeartbleed-styleKlue breachMastraNPM supply chainNorth KoreaPopa Android TV botnetShinyHuntersSquid proxySquidbleedTexas Parks & WildlifeUsbliter8Velvet AntWordPress plugincredential harvestingdata breachesiPhone unpatchable exploitsupply chain attackthird-party vendor breach
What happened
Multiple high-impact disclosures and active campaigns: a decades-old Squid proxy flaw (“Squidbleed”) can leak user data (Heartbleed-like); a Gravity SMTP WordPress plugin bug is being exploited to leak API keys/secrets; a North Korea-linked malicious dependency was injected into 140+ Mastra NPM packages targeting crypto extensions; an unpatchable Usbliter8 boot exploit with a public PoC affects millions of iPhones; Fortinet credential-harvesting “FortiBleed” campaign produced a database of ~86,000 working credentials; and the Klue breach has impacted many cybersecurity vendors. Other notable:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 54c25211a8045c97e7fa97c4c713347c41542a06bf9a23e17e73b9341a06b6b1
- Enrichment time
- 2026-06-22T13:24:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.