Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data
2026-06-22T19:24:05Z•9987b38aa59577ede6d1dbd74b06ae9d6d3604bb5f35d2118197de6a129ec8c2
ai-regulationandroid-tv-botnetapple-boot-exploitbeats-eavesdroppingcredential-harvestcryptomining-malwaredata-breachfortibleedgcp-config-connectorgravity-smtpheartbleed-styleklue-hackmastranpmpopa-botnetshinyhunterssquid-proxysquidbleedsupply-chain-attacktexas-parks-wildlifethird-party-vendorusbliter8velvet-antwordpress-plugin
What happened
Multiple high-impact security stories: a decades-old Squid proxy flaw dubbed “Squidbleed” (Heartbleed-style) can expose user data; attackers are actively exploiting a Gravity SMTP WordPress plugin to leak API keys, tokens and server info; a North Korean-linked supply-chain compromise injected malicious code into 140+ Mastra NPM packages targeting crypto extensions; and an unpatchable Usbliter8 boot exploit affecting millions of iPhones has a released PoC. Other notable incidents include the FortiBleed credential-harvesting campaign, ongoing Klue customer impact and breaches (including ShinyHun
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 9987b38aa59577ede6d1dbd74b06ae9d6d3604bb5f35d2118197de6a129ec8c2
- Enrichment time
- 2026-06-22T19:24:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.