43AA 6E9A 54EE B550 D830 EF7A 36EE 72FB 8AD1 F5CC

Infosec bits for 2026 week 25

Zoya Vilakazi | June 19, 2026, 4:13 p.m.

Cybersecurity News:

  • CISA Urges Hardening Fortinet Devices Following FortiBleed Attack [Abinaya, Cyber Security News]
  • Galeboe awarded Premier Partner status for Check Point, strengthening AI-driven cyber security across SA and beyond [Galeboe Professional Services, IT Web]
  • Hackers Abuse Claude.ai Shared Chat Feature to Host the ClickFix Social Engineering Instructions [Abinaya, Cyber Security News]
  • Vulnerabilities & Patches:

  • F5 issues out-of-band patches for critical NGINX vulnerabilities [Sergiu Gatlan, Bleeping Computer]
  • Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities [Ionut Arghire, Security Week]
  • Critical Node.js Security Release Patches 12 Vulnerabilities Including Authentication Bypass [Lucas Martin, Cyber Press]
  • Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone [Ravie Lakshmanan, The Hacker News]
  • Fortra Access Manager Vulnerability Enables Remote Command Injection Attacks [Abinaya, Cyber Security News]
  • Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks [Abinaya, Cyber Security News]
  • Threats & Malware:

  • Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2 [Ravie Lakshmanan, The Hacker News]
  • CryptoBandits Malware Doubles as a Backdoor, Abuses Tor [Ionut Arghire, Security Week]
  • Windows version of SprySOCKS Linux malware used to attack govt orgs [Bill Toulas, Bleeping Computer]
  • Cybercriminals abused GitHub, YouTube and VirusTotal to push crypto-stealing malware [Sinisa Markovic, Help Net Security]
  • INC Ransomware Uses Rust-Based Windows and Linux/ESXi Encryptors in New Attacks [Tushar Subhra Dutta, Cyber Security News]
  • Attacks & Data Breaches:

  • FortiBleed – 70,000+ Fortinet Firewalls Compromised in Massive Exploitation Attack [Guru Baran, Cyber Security News]
  • Compromised coding tool helped hackers breach thousands of GitHub repositories [Eric Geller, Cybersecurity Dive]
  • Low-skilled attacker used Claude, Codex to breach 14 companies [Zeljka Zorz, Help Net Security]