Dawn of the Apex Agentic Adversary

2026-06-24T13:24:08Zc6bc2d4cfb82d76e60de615c3d78f5aba45a3a18b68c621ebfe3b56225ae5822
AI-securityAryStingerAutoJackCVE-2026-20230CVE-2026-4020EDR-evasionFortiBleedFortiGateGentleKillerIoT-botnetManageEngineSecureROMSquidbleedWhatsApp-phishingagentic-aicredential-harvestingexploitmalwarenpm-malwareproxy-malwareransomwareremote-access-trojansupply_chain_attackusbliter8vulnerability

What happened

A wide-ranging security roundup: threat actors are actively exploiting recently disclosed vulnerabilities and running large-scale credential-harvesting and malware campaigns while supply-chain and agentic-AI risks rise. Notable technical incidents include active exploitation of Cisco Unified Communications Manager (CVE-2026-20230, CVSS 8.6), a massive FortiGate credential-harvesting operation (FortiBleed), malicious npm packages delivering a Windows RAT, WhatsApp-distributed VBScript installers for ManageEngine RMM, supply-chain backdoors in ShapedPlugin WordPress plugins, and a new OXLOADER/C

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
c6bc2d4cfb82d76e60de615c3d78f5aba45a3a18b68c621ebfe3b56225ae5822
Enrichment time
2026-06-24T13:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Dawn of the Apex Agentic Adversary · Baitaphish