FortiBleed – 70,000+ Fortinet Firewalls Compromised in Massive Exploitation Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 An exhaustive cyber espionage campaign now dubbed “FortiBleed” has silently compromised over 73,932 unique Fortinet firewall URLs across 194 countries. Originally uncovered by security researcher Volodymyr “Bob” Diachenko and subsequently …

FishMonger Hackers Expands SprySOCKS Backdoor From Linux to Windows With Advanced Stealth Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A well-known Chinese cyberespionage group has taken a major step forward in its hacking capabilities. The threat actor, tracked as FishMonger, has brought its SprySOCKS backdoor to Windows for the …

ErrTraffic MaaS Uses Fake reCAPTCHA and Cloudflare Turnstile Lures to Execute PowerShell Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 A new and rapidly growing cybercrime tool called ErrTraffic is making waves across the threat landscape, targeting internet users through cleverly disguised verification screens. The framework tricks …

Multiple JetBrains IDE Plugins 70,000+ Installs Caught Stealing AI keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 A large-scale malware campaign has been uncovered on the JetBrains Marketplace, where at least 15 malicious IDE plugins were found stealing sensitive API keys from developers. These …

CISA Warns of Oracle PeopleSoft 0-Day Vulnerability Exploited in Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 CISA has added a critical Oracle PeopleSoft vulnerability, tracked as CVE-2026-35273, to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. The flaw affects …

Fortra Access Manager Vulnerability Enables Remote Command Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 Fortra has disclosed a critical security vulnerability in its Core Privileged Access Manager (BoKS) that could allow remote attackers to execute arbitrary commands on affected systems. CVE-2026-9862 …

U.S. Commerce Dept Imposes Export Controls on Anthropic’s Claude Mythos 5 and Fable 5

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 The Bureau of Industry and Security (BIS) has issued a landmark “Is Informed” letter to Anthropic CEO Dario Amodei, mandating that the company obtain an individually validated …

Hackers Compromised 140+ Mastra npm Packages to Deploy Password-Stealing Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 A sophisticated supply chain attack has targeted the Mastra-AI npm ecosystem, with researchers from Microsoft and Socket identifying over 141 compromised packages designed to silently deploy an …

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 AIRecon is an autonomous penetration testing agent that runs entirely offline, combining a self-hosted Ollama LLM with a Kali Linux Docker sandbox to automate end-to-end security assessments …

Critical LiteLLM Flaw Allows Authentication Bypass via Host Header Injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 A critical security vulnerability has been disclosed in LiteLLM, an increasingly popular proxy used for managing large language model (LLM) APIs. The flaw, tracked as CVE-2026-49468, allows …