Google told researcher 'Nice catch!' Then denied bug bounty for flaw it still hasn't fixed
2026-06-18T19:23:58Z•c71496e4fbaeda541eccff050095aaf6c8e98319b3f0eb6427475455270b4c8b
0-dayAURBitLocker bypassCatalyst SD‑WANCisco SD‑WANFortiGateFortinetFortinet sandbox bugsGitHubIvanti SentryNovo NordiskOracle PeopleSoftShinyHuntersWindowscredential exposuredata breachhealthcaremake-me-rootmiasmanpmpassword-theftremote RCEsupply-chaintelecom
What happened
Multiple active, high-impact incidents and vulnerabilities reported across networking, endpoint and enterprise apps: mass password-stealing campaign targeting ~75k Fortinet firewalls; multiple critical Fortinet sandbox bugs and Cisco SD‑WAN/Catalyst SD‑WAN manager flaws being exploited (including an 0-day/make-me-root); Ivanti Sentry remote unauthenticated RCEs; Oracle PeopleSoft 0-day used by ShinyHunters against 100+ orgs (Council of Europe, universities); new Windows/BitLocker bypass 0-days; and several data breaches impacting healthcare and enterprise (Novo Nordisk, cardiac monitor vendor)
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- c71496e4fbaeda541eccff050095aaf6c8e98319b3f0eb6427475455270b4c8b
- Enrichment time
- 2026-06-18T19:23:58Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.