Google told researcher 'Nice catch!' Then denied bug bounty for flaw it still hasn't fixed

2026-06-18T19:23:58Zc71496e4fbaeda541eccff050095aaf6c8e98319b3f0eb6427475455270b4c8b
0-dayAURBitLocker bypassCatalyst SD‑WANCisco SD‑WANFortiGateFortinetFortinet sandbox bugsGitHubIvanti SentryNovo NordiskOracle PeopleSoftShinyHuntersWindowscredential exposuredata breachhealthcaremake-me-rootmiasmanpmpassword-theftremote RCEsupply-chaintelecom

What happened

Multiple active, high-impact incidents and vulnerabilities reported across networking, endpoint and enterprise apps: mass password-stealing campaign targeting ~75k Fortinet firewalls; multiple critical Fortinet sandbox bugs and Cisco SD‑WAN/Catalyst SD‑WAN manager flaws being exploited (including an 0-day/make-me-root); Ivanti Sentry remote unauthenticated RCEs; Oracle PeopleSoft 0-day used by ShinyHunters against 100+ orgs (Council of Europe, universities); new Windows/BitLocker bypass 0-days; and several data breaches impacting healthcare and enterprise (Novo Nordisk, cardiac monitor vendor)

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
c71496e4fbaeda541eccff050095aaf6c8e98319b3f0eb6427475455270b4c8b
Enrichment time
2026-06-18T19:23:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.