Dawn of the Apex Agentic Adversary
2026-06-24T13:24:08Z•c6bc2d4cfb82d76e60de615c3d78f5aba45a3a18b68c621ebfe3b56225ae5822
AI-securityAryStingerAutoJackCVE-2026-20230CVE-2026-4020EDR-evasionFortiBleedFortiGateGentleKillerIoT-botnetManageEngineSecureROMSquidbleedWhatsApp-phishingagentic-aicredential-harvestingexploitmalwarenpm-malwareproxy-malwareransomwareremote-access-trojansupply_chain_attackusbliter8vulnerability
What happened
A wide-ranging security roundup: threat actors are actively exploiting recently disclosed vulnerabilities and running large-scale credential-harvesting and malware campaigns while supply-chain and agentic-AI risks rise. Notable technical incidents include active exploitation of Cisco Unified Communications Manager (CVE-2026-20230, CVSS 8.6), a massive FortiGate credential-harvesting operation (FortiBleed), malicious npm packages delivering a Windows RAT, WhatsApp-distributed VBScript installers for ManageEngine RMM, supply-chain backdoors in ShapedPlugin WordPress plugins, and a new OXLOADER/C
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- c6bc2d4cfb82d76e60de615c3d78f5aba45a3a18b68c621ebfe3b56225ae5822
- Enrichment time
- 2026-06-24T13:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.