Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments

2026-06-17T19:24:11Z11000d6ff19b0a2c4dd9547d11a1f3024f984afacc646e74697bb9fa66bd58e6
AI securityCISAChrome extensionsCopilot SearchLeakFortiSandboxKEVLiteLLMNarwhalRATRokarollaTailscaleWordPress backdooractive exploitationbackdoormalicious pluginsmodel SDKnpm compromisepatches availablepersistencepicklingprivilege escalationsupply chain compromisezero-day

What happened

This collection of The Hacker News stories (June 15–17, 2026) details multiple active campaigns, supply‑chain compromises, and high‑impact vulnerabilities. Notable highlights: CISA added a maximum‑severity Joomla JCE flaw (CVE‑2026‑48907, CVSS 10.0) with evidence of active exploitation; Microsoft disclosed a Defender elevation‑of‑privilege zero‑day (RoguePlanet, CVE‑2026‑50656) with a patch in development; multiple Fortinet FortiSandbox flaws (CVE‑2026‑39813, CVE‑2026‑39808, CVE‑2026‑25089) are being exploited; Cisco released fixes for an actively exploited SD‑WAN Manager bug (CVE‑2026‑20262);

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
11000d6ff19b0a2c4dd9547d11a1f3024f984afacc646e74697bb9fa66bd58e6
Enrichment time
2026-06-17T19:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.