FortiBleed harvests 110M credentials; Cisco SSRF actively exploited; GitHub patches CI/CD attacks
ID: 4d90ab01-81d9-54e2-9e60-5eda13ea685d
STIX ID: report--4d90ab01-81d9-54e2-9e60-5eda13ea685d
Feed Name: defend.network
This briefing reports multiple high-risk incidents: the FortiBleed campaign harvested ~110 million credentials from ~430,000 FortiGate devices; CVE-2026-20230 (Cisco Unified CM SSRF) is being actively exploited; AI agent skill supply-chain weaknesses and Dify multi-tenant flaws expose chat histories and documents; GitHub patched actions/checkout to block pwn-request attacks. Recommended immediate actions include patching or isolating affected systems, rotating exposed credentials, auditing AI skills and GitHub workflows, and monitoring for related indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
