A Russian-speaking initial access broker is behind the FortiBleed operation, targeting over 430,000 FortiGate firewalls worldwide. Active since February 2026, the campaign focuses on credential harvesting, exploiting exposed services, and deploying tailored malware to gain unauthorized access.
- •FortiBleed targets FortiGate firewalls globally.
- •Over 430,000 devices have been compromised.
- •The operation is financially motivated by a Russian-speaking group.
Why it matters: This operation highlights vulnerabilities in widely used security infrastructure, signaling a need for enhanced cybersecurity measures. The scale of the attack could pressure organizations to reassess their firewall configurations and incident response strategies.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of a critical security flaw in Lantronix EDS5000 devices. The vulnerability, identified as CVE-2025-67038, has a CVSS score of 9.8 and poses significant risks, prompting agencies to implement fixes by June 26, 2026.
- •CISA warns of a critical flaw in Lantronix EDS5000 devices.
- •The vulnerability is a code injection issue with a CVSS score of 9.8.
- •Active exploitation of this flaw has been reported.
Why it matters: This situation highlights the urgent need for organizations to prioritize cybersecurity measures, as unpatched vulnerabilities can lead to significant operational disruptions and data breaches. It also pressures companies to enhance their security protocols to protect against active threats.
Online retailers and Anatel have reached an agreement to combat the sale of miniature cell phones, which are used in prisons and pose risks to public safety. The agreement requires platforms to develop technologies, including artificial intelligence, to verify the certification of devices. The goal is to enhance oversight and reduce the sale of these devices that bypass surveillance systems.
- •Anatel and online retailers reach agreement against miniature cell phones.
- •Miniature cell phones are used in prisons, bypassing surveillance.
- •Agreement involves marketplaces like Amazon and Mercado Livre.
Why it matters: This agreement signals a collaborative effort to mitigate public safety risks by pressuring platforms to adopt more robust technologies. It may lead to increased regulation of e-commerce and the need for innovation in oversight systems, impacting how companies operate and adapt to new legal requirements.
Uma operação coordenada de aplicação da lei, em parceria com empresas do setor privado, resultou na desarticulação da infraestrutura criminosa que alimentava os malwares Amadey e StealC, recuperando 27 milhões de credenciais roubadas. O objetivo era interromper as 'linhas de montagem' que os cibercriminosos usam para lançar ataques.
- •Operação conjunta desarticulou a rede de malwares Amadey e StealC.
- •27 milhões de credenciais roubadas foram recuperadas.
- •Parceria incluiu empresas como Bitdefender e Microsoft.
Why it matters: A desarticulação dessas redes de malware sinaliza um avanço significativo na luta contra o cibercrime, pressionando criminosos a mudar suas táticas e aumentando a segurança em setores críticos. Isso pode reduzir custos associados a fraudes e ataques cibernéticos para empresas e governos.
Cybersecurity researchers have identified a critical CI/CD workflow vulnerability, dubbed Cordyceps, that could enable attackers to hijack workflows and compromise open-source supply chains. This flaw affects over 300 GitHub repositories, including those of major organizations like Microsoft and Google, raising significant concerns about supply chain security.
- •New CI/CD vulnerability named Cordyceps discovered.
- •Exposes over 300 GitHub repositories to supply chain attacks.
- •Affects major organizations including Microsoft and Google.
Why it matters: This vulnerability signals a pressing need for organizations to reassess their CI/CD security practices, as compromised workflows can lead to widespread disruptions and loss of trust in open-source software. The implications extend to regulatory scrutiny and potential financial losses for affected companies.
We are witnessing the end of an era in cybersecurity, transitioning from human-speed threats to more sophisticated adversaries. Previously, vulnerabilities were identified and patched in a predictable cycle, but now, organizations face challenges from faster, more agile threats that require a reevaluation of existing security protocols and response times.
- •Cybersecurity is evolving beyond human-speed threats.
- •Organizations must adapt to faster, more sophisticated adversaries.
- •Traditional patch cycles are becoming inadequate.
Why it matters: This shift signals a pressing need for organizations to enhance their cybersecurity frameworks, as traditional methods may no longer suffice. The implications could lead to increased operational costs and a greater emphasis on real-time threat detection and response strategies.
Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). The vulnerability, tracked as CVE-2026-20230 (CVSS score: 8.6), is a case of improper input validation for specific HTTP requests that could allow an unauthenticated, remote attacker to write files to the system.
- •Cisco Unified CM is facing a critical security flaw.
- •The vulnerability is tracked as CVE-2026-20230 with a CVSS score of 8.6.
- •Improper input validation for specific HTTP requests is the root cause.
Why it matters: This vulnerability highlights significant risks in enterprise communication systems, potentially exposing sensitive data and disrupting operations. Organizations must prioritize security patches to maintain trust and compliance in their communication infrastructure.