Google told researcher 'Nice catch!' Then denied bug bounty for flaw it still hasn't fixed

2026-06-19T07:24:00Zc5267e3aab6177d8a0179fdeefc3bcb4c1e7977781273c4b033778fb6fee74c9
aurbitlockerciscocredential-theftdata-breachespionageexploitationfortinetivantimass-compromisemicrosoftnpmopen-source-securityoracle-peoplesoftpatchingprc-linkedshinyhunterssupply-chainvulnerabilityzero-day

What happened

Collection of security news (mid-June 2026) showing multiple actively exploited and critical vulnerabilities, large credential-theft campaigns, supply-chain risks, and high-profile breaches. Notable items: mass password‑stealing attacks impacting ~75k Fortinet firewalls and multiple critical Fortinet sandbox bugs under attack; Cisco SD‑WAN/Catalyst SD‑WAN Manager make-me-root/0‑day activity; Ivanti Sentry remote unauthenticated RCEs rated critical; Oracle PeopleSoft 0‑day exploited by ShinyHunters affecting 100+ orgs (including Council of Europe/Nottingham); Windows/BitLocker bypass and new 0‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
c5267e3aab6177d8a0179fdeefc3bcb4c1e7977781273c4b033778fb6fee74c9
Enrichment time
2026-06-19T07:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.