logo

FortiBleed harvests 110M credentials; Cisco SSRF actively exploited; GitHub patches CI/CD attacks

ID: 4d90ab01-81d9-54e2-9e60-5eda13ea685d

STIX ID: report--4d90ab01-81d9-54e2-9e60-5eda13ea685d

Feed Name: defend.network

Threat Score
78/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

...
...

This briefing reports multiple high-risk incidents: the FortiBleed campaign harvested ~110 million credentials from ~430,000 FortiGate devices; CVE-2026-20230 (Cisco Unified CM SSRF) is being actively exploited; AI agent skill supply-chain weaknesses and Dify multi-tenant flaws expose chat histories and documents; GitHub patched actions/checkout to block pwn-request attacks. Recommended immediate actions include patching or isolating affected systems, rotating exposed credentials, auditing AI skills and GitHub workflows, and monitoring for related indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.