You have got to be KDDI-ng – Japanese telco exposes 14.2 million managed email credentials
2026-06-24T07:24:04Z•e1a0eca18b69ca01e8870e854967222227dd12844d8f9d3719b737bc3c5ed148
CiscoFortinetKDDISD‑WANSquidactive‑exploitationbootromcheckm8credential‑exposuredata‑breachextortioniphonemalwarememory‑leaknation‑statepeople‑softphishingsupply‑chaintelcozero‑day
What happened
Collection of mid‑June 2026 security news: major exposure of 14.2M managed email credentials at Japanese telco KDDI; wide‑scale active exploitation and credential theft affecting network gear (75k Fortinet firewalls, multiple critical Fortinet sandbox bugs, and a Cisco SD‑WAN make‑me‑root zero‑day under attack); a new checkm8‑style BootROM exploit for A12/A13 iPhones; 'Squidbleed' memory‑leak in Squid; multiple data breaches and extortion incidents (Council of Europe PeopleSoft heist, Klue/ Icarus victims, Novo Nordisk clinical‑trial data); and various phishing/malware campaigns (ClickFix, C2s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- e1a0eca18b69ca01e8870e854967222227dd12844d8f9d3719b737bc3c5ed148
- Enrichment time
- 2026-06-24T07:24:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.