Google told researcher 'Nice catch!' Then denied bug bounty for flaw it still hasn't fixed
2026-06-19T07:24:00Z•c5267e3aab6177d8a0179fdeefc3bcb4c1e7977781273c4b033778fb6fee74c9
aurbitlockerciscocredential-theftdata-breachespionageexploitationfortinetivantimass-compromisemicrosoftnpmopen-source-securityoracle-peoplesoftpatchingprc-linkedshinyhunterssupply-chainvulnerabilityzero-day
What happened
Collection of security news (mid-June 2026) showing multiple actively exploited and critical vulnerabilities, large credential-theft campaigns, supply-chain risks, and high-profile breaches. Notable items: mass password‑stealing attacks impacting ~75k Fortinet firewalls and multiple critical Fortinet sandbox bugs under attack; Cisco SD‑WAN/Catalyst SD‑WAN Manager make-me-root/0‑day activity; Ivanti Sentry remote unauthenticated RCEs rated critical; Oracle PeopleSoft 0‑day exploited by ShinyHunters affecting 100+ orgs (including Council of Europe/Nottingham); Windows/BitLocker bypass and new 0‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- c5267e3aab6177d8a0179fdeefc3bcb4c1e7977781273c4b033778fb6fee74c9
- Enrichment time
- 2026-06-19T07:24:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.