Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data

2026-06-23T01:24:05Ze2233ac79ea76f178259d4a7d12f959de0f918d2608b4f76d86144f9a7ec8959
ai-regulationapi-keysapple-bootromcredential-harvestdata-breachemmanuel-macron','apple-beats-patch','android-tbot-popa','velvetfortibleedfortinetgravity-smtpheartbleed-styleiphone-exploitklue-hackmastranorth-koreanpmsecretsshinyhunterssquid-proxysquidbleedsupply-chaintexas-parks-and-wildlifethird-party-vendortokensusbliter8wordpress-plugin

What happened

A batch of high-impact security stories: “Squidbleed,” a decades-old Squid proxy vulnerability likened to Heartbleed, can expose user data; Gravity Forms SMTP plugin flaws are being actively exploited to leak API keys, tokens and server information; and a Mastra NPM supply-chain campaign (attributed to North Korean actors) injected a malicious dependency into 140+ packages to target cryptocurrency extensions. Researchers released an unpatchable Usbliter8 boot exploit affecting millions of iPhones, while Fortinet’s “FortiBleed” credential-harvesting campaign amassed a database of >86,000 valids

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
e2233ac79ea76f178259d4a7d12f959de0f918d2608b4f76d86144f9a7ec8959
Enrichment time
2026-06-23T01:24:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.