It's looking like a hot, messy summer for security teams as AI finds countless previously hidden vulns
2026-06-27T07:24:01Z•e86b31af624e1ea64f65a3c74dff16181e83906cdbcb9193981043df457efd61
Amazon-QCVE-2026-20230CiscoFortinetMisticaccess-brokeraibackdoorbootromcredential-theftexploitationincident-responseinfrastructure-compromiseiphonemalicious-git-reposmiasmanation-statenpmpatchingransomwaresupply-chainvulnerability-discoveryzero-day
What happened
News roundup: a surge in AI-assisted vulnerability discovery and exploitation is driving a ‘hot, messy’ period for security teams. Active incidents include exploitation of Cisco CVE-2026-20230, multiple critical Fortinet sandbox/SD-WAN vulnerabilities and a massive password-stealing campaign hitting ~75k Fortinet firewalls, the Miasma campaign poisoning 20+ npm packages to harvest developer secrets, an Amazon Q flaw that lets booby-trapped Git repos execute commands and steal cloud credentials, and a self‑destructing Mistic backdoor sold by an access broker to ransomware groups. Other notable:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- e86b31af624e1ea64f65a3c74dff16181e83906cdbcb9193981043df457efd61
- Enrichment time
- 2026-06-27T07:24:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.