You have got to be KDDI-ng – Japanese telco exposes 14.2 million managed email credentials

2026-06-24T07:24:04Ze1a0eca18b69ca01e8870e854967222227dd12844d8f9d3719b737bc3c5ed148
CiscoFortinetKDDISD‑WANSquidactive‑exploitationbootromcheckm8credential‑exposuredata‑breachextortioniphonemalwarememory‑leaknation‑statepeople‑softphishingsupply‑chaintelcozero‑day

What happened

Collection of mid‑June 2026 security news: major exposure of 14.2M managed email credentials at Japanese telco KDDI; wide‑scale active exploitation and credential theft affecting network gear (75k Fortinet firewalls, multiple critical Fortinet sandbox bugs, and a Cisco SD‑WAN make‑me‑root zero‑day under attack); a new checkm8‑style BootROM exploit for A12/A13 iPhones; 'Squidbleed' memory‑leak in Squid; multiple data breaches and extortion incidents (Council of Europe PeopleSoft heist, Klue/ Icarus victims, Novo Nordisk clinical‑trial data); and various phishing/malware campaigns (ClickFix, C2s

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
e1a0eca18b69ca01e8870e854967222227dd12844d8f9d3719b737bc3c5ed148
Enrichment time
2026-06-24T07:24:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.