Top 10 Cybersecurity Updates , June 19–26, 2026

Jun 26 2026

.bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
.bh__table_cell { padding: 5px; background-color: #FFFFFF; }
.bh__table_cell p { color: #2D2D2D; font-family: ‘Helvetica’,Arial,sans-serif !important; overflow-wrap: break-word; }
.bh__table_header { padding: 5px; background-color:#F1F1F1; }
.bh__table_header p { color: #2A2A2A; font-family:’Trebuchet MS’,’Lucida Grande’,Tahoma,sans-serif !important; overflow-wrap: break-word; }

Gone Phishing Banner

Welcome to Gone Phishing, where the only thing getting hooked is bad actors. No bots, no fluff, just the week's most dangerous catches. 🎣

In partnership with

Detect, investigate, and respond to threats faster with Splunk Enterprise — the industry-leading SIEM trusted by thousands of organizations worldwide.

Splunk Enterprise delivers real-time visibility across your entire environment. With AI-powered detection, Risk-Based Alerting, and 1,800+ out-of-the-box detections mapped to MITRE ATT&CK, your SOC can cut alert fatigue and stay focused on the threats that matter most.

Top 10 Cybersecurity Updates , June 19–26, 2026


1. Salesforce supply-chain breach widens as 'Icarus' leaks Klue OAuth data An OAuth-token compromise at vendor Klue let the Icarus extortion crew pivot into customers' Salesforce environments. The victim list grew through the week to HackerOne, Huntress, Recorded Future, Tanium, BeyondTrust, LastPass and Gong; Salesforce disabled the integration. Audit connected apps and revoke unused OAuth tokens. Read more →

2. 'FortiBleed' credential heist compromises 30,000+ FortiGate devices Suspected Russian-speaking actors are scraping FortiGate config files, cracking hashes and using compromised boxes to harvest VPN credentials across 194 countries. CISA issued hardening guidance — terminate sessions and reset all device/VPN credentials. Read more →

3. Texas Parks & Wildlife vendor breach exposes 3 million hunters and anglers A breach at the license-system vendor exposed driver's license and passport numbers plus contact data for 3,087,721 people (no SSNs/financials). Free Kroll monitoring through 14 Sept. Read more →

4. 24 billion stolen credentials found on an open Elasticsearch cluster One of the largest aggregated credential troves ever — and enriched with live CVE data to prioritise exploitable targets. Direct fuel for credential-stuffing; enforce MFA, kill password reuse. Read more →

5. 'DifyTap' flaws let attackers wiretap AI chats across 1M+ apps Four bugs in the open-source Dify AI platform (CVE-2026-41947, CVSS 9.1) let attackers establish a persistent exfiltration channel for every prompt/response, with cross-tenant impact. Upgrade to Dify 1.14.2. Read more →

6. Critical libssh2 flaw (CVE-2026-55200) enables pre-auth RCE on all versions A CVSS 9.2 heap overflow allows unauthenticated RCE via a crafted SSH packet. Embedded in curl, backup tools and countless IoT devices; PoC public. Rebuild dependents once a tagged release lands. Read more →

7. CISA adds actively-exploited Lantronix and Ubiquiti device flaws to KEV Lantronix EDS5000 command-injection (CVE-2025-67038, CVSS 9.8) gives root with no password, plus max-severity Ubiquiti UniFi OS flaws. Federal patch deadline 26 June; patch EDS5000 to 2.2.0.0R1. Read more →

8. Cisco's bad week: new UC Manager SSRF zero-day exploited over the weekend CVE-2026-20230 (UC Manager SSRF) was seen exploited 21–22 June, on top of the SD-WAN Manager zero-day (CVE-2026-20245) — the seventh confirmed exploited Cisco SD-WAN bug of 2026. Prioritise edge/management-plane patching. Read more →

9. Operation Endgame dismantles SocGholish, StealC and Amadey infrastructure Europol-coordinated police took down 100+ SocGholish servers (linked to Evil Corp), cleaned 14,971 WordPress sites, and this week disrupted the StealC and Amadey infostealers. A rare defensive win. Read more →

10. 'Cordyceps' CI/CD flaw exposes 300+ GitHub repos at Microsoft, Google, Apache A systemic GitHub Actions weakness chains untrusted-PR output into privileged workflows for repo takeover — 654 vulnerable projects found. Notably, AI coding agents reproduce the insecure pattern at scale. Read more →


Key Themes This Week

  • Trust boundaries are the new perimeter — the biggest hits came via OAuth integrations, CI/CD pipelines, shared libraries and AI platforms, not direct breaches.

  • Credentials at industrial scale — FortiBleed and a 24-billion-record infostealer DB, both weaponised with live CVE data, make MFA/rotation non-negotiable.

  • Edge and OT stay under active fire — Cisco, Lantronix and Ubiquiti all hit exploitation/KEV this week.

Let us know what you think.

So long and thanks for reading all the phish!

footer graphic cyber security newsletter

Recent articles