Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data
2026-06-23T01:24:05Z•e2233ac79ea76f178259d4a7d12f959de0f918d2608b4f76d86144f9a7ec8959
ai-regulationapi-keysapple-bootromcredential-harvestdata-breachemmanuel-macron','apple-beats-patch','android-tbot-popa','velvetfortibleedfortinetgravity-smtpheartbleed-styleiphone-exploitklue-hackmastranorth-koreanpmsecretsshinyhunterssquid-proxysquidbleedsupply-chaintexas-parks-and-wildlifethird-party-vendortokensusbliter8wordpress-plugin
What happened
A batch of high-impact security stories: “Squidbleed,” a decades-old Squid proxy vulnerability likened to Heartbleed, can expose user data; Gravity Forms SMTP plugin flaws are being actively exploited to leak API keys, tokens and server information; and a Mastra NPM supply-chain campaign (attributed to North Korean actors) injected a malicious dependency into 140+ packages to target cryptocurrency extensions. Researchers released an unpatchable Usbliter8 boot exploit affecting millions of iPhones, while Fortinet’s “FortiBleed” credential-harvesting campaign amassed a database of >86,000 valids
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- e2233ac79ea76f178259d4a7d12f959de0f918d2608b4f76d86144f9a7ec8959
- Enrichment time
- 2026-06-23T01:24:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.