THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
FortiBleed: CISA Warns of Active Exploitation After 74,000 Fortinet Credential Leak

CISA issued an emergency alert after reports surfaced that credentials tied to roughly 74,000 Fortinet firewalls and VPN gateways were leaked. The agency confirmed threat actors are actively exploiting the exposure to target systems worldwide. Organizations using affected Fortinet products should urgently validate access, rotate credentials, and review authentication logs for suspicious patterns.

Source: Security Affairs


FortiBleed Exposed an Industrial-Scale Credential-Spraying Operation Against Fortinet VPNs

Researchers say FortiBleed wasn’t a one-off intrusion—it functioned like a “factory” for generating and trying credentials at massive scale. A multi-operator crew reportedly carried out billions of login attempts against Fortinet FortiGate SSL VPNs, compromising organizations globally. The key takeaway for defenders: credential hygiene and VPN hardening (MFA, rate limiting, geo/behavioral controls) are essential because this class of attack thrives on volume and automation.

Source: Security Affairs


Week in Review: 74K Fortinet Credentials Stolen as Splunk Enterprise RCE Is Reported Under Active Attack

A recap of the week’s most consequential security developments highlights two major themes: large-scale Fortinet credential theft and escalating exploitation risk around widely deployed monitoring platforms. The reporting flags that Splunk Enterprise RCE concerns are under active attack, raising the urgency of patching and exposure reduction. For security teams, this is another reminder that internet-facing infrastructure plus rapid-turn patching windows often determine whether an incident becomes widespread.

Source: Help Net Security


GentleKiller: “EDR-Killer” Tooling Uses BYOVD to Disable Security Before Ransomware Strikes

ESET describes “The Gentlemen” infrastructure powering GentleKiller, a suite designed to quickly neutralize endpoint defenses. The group weaponizes BYOVD (Bring Your Own Vulnerable Driver) techniques to disable or degrade security tooling, clearing the way for ransomware or follow-on attacks. Defenders should prioritize EDR resilience, driver-control policies, and rapid detection of defense-evasion behaviors—not just malware indicators.

Source: Security Affairs


Gravity SMTP (WordPress): Hackers Exploit CVE-2026-4020 to Steal API Keys and OAuth Tokens

Threat actors are reportedly exploiting a patched vulnerability in the Gravity SMTP WordPress plugin to expose sensitive secrets. The flaw, CVE-2026-4020 (CVSS 5.3), can enable unauthenticated attackers to extract configuration data including API keys, OAuth tokens, and other secrets. WordPress operators should ensure the plugin is updated immediately, then rotate any potentially exposed credentials.

Source: The Hacker News


Deadlines for Secure Boot Crypto: Windows and Linux Security Keys Start Expiring on June 24

ThreatLevel reports that cryptographic keys securing the boot sequence begin expiring on June 24 for both Windows and Linux environments. While expiration doesn’t automatically mean systems fail to boot, it can reduce trust or break update and verification paths—creating a window where security expectations drift from reality. Organizations should confirm they’re on supported versions, apply necessary updates, and validate secure boot/attestation health ahead of the deadline.

Source: 'Wired' / ThreatLevel


You May Also Be Interested In...

French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation
MDR Provider Comparison: Time to Discover and Respond to Threats
AI, Mind Reading and Microchip Brain Implants

Cybersecurity — June 21, 2026 | Briefing24