Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data

2026-06-22T19:24:05Z9987b38aa59577ede6d1dbd74b06ae9d6d3604bb5f35d2118197de6a129ec8c2
ai-regulationandroid-tv-botnetapple-boot-exploitbeats-eavesdroppingcredential-harvestcryptomining-malwaredata-breachfortibleedgcp-config-connectorgravity-smtpheartbleed-styleklue-hackmastranpmpopa-botnetshinyhunterssquid-proxysquidbleedsupply-chain-attacktexas-parks-wildlifethird-party-vendorusbliter8velvet-antwordpress-plugin

What happened

Multiple high-impact security stories: a decades-old Squid proxy flaw dubbed “Squidbleed” (Heartbleed-style) can expose user data; attackers are actively exploiting a Gravity SMTP WordPress plugin to leak API keys, tokens and server info; a North Korean-linked supply-chain compromise injected malicious code into 140+ Mastra NPM packages targeting crypto extensions; and an unpatchable Usbliter8 boot exploit affecting millions of iPhones has a released PoC. Other notable incidents include the FortiBleed credential-harvesting campaign, ongoing Klue customer impact and breaches (including ShinyHun

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
9987b38aa59577ede6d1dbd74b06ae9d6d3604bb5f35d2118197de6a129ec8c2
Enrichment time
2026-06-22T19:24:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.