A massive attack on 75,000 Fortinet firewalls across 194 countries has stolen credentials from major corporations like FoxConn, Samsung, and Oracle, with some networks fully compromised.
securitySaturday, June 20, 2026
Fortinet breach and AI-powered scams dominate security news
Today's security landscape is a tale of two threats: massive, old-school attacks on infrastructure and a new wave of AI-augmented social engineering. The Fortinet firewall compromise shows that traditional network devices remain juicy targets, while the rise of AI-generated phishing and MCP exploitation proves attackers are quick to adopt new tools. Even criminals are worried about AI taking their jobs.
Infrastructure under siege
The biggest story today is a massive credential theft from Fortinet firewalls, but it's not the only infrastructure attack making headlines.
Ivanti Sentry has a pre-auth RCE vulnerability with a CVSS 10 score, a rare and critical flaw that attackers can exploit remotely without authentication.
Hackers are mass-exploiting a Gravity SMTP WordPress plugin flaw on 100,000 sites to steal API keys, two months after the patch was released.
AI amplifies social engineering
Attackers are weaponizing AI to make scams more convincing, from personalized phishing to fake CAPTCHA malware.
Scams are at an all-time high, with AI-generated phishing messages that are grammatically flawless and personalized, costing Americans $119 billion annually.
The ClickFix scam tricks users into pressing keyboard shortcuts to download malware, mimicking CAPTCHA tests and going mainstream after targeted attacks last year.
Sophos research shows cybercriminals on dark web forums fear AI will automate hacking tasks and replace their manual services, mirroring legitimate industry concerns.
New vulnerabilities and exploits
A handful of critical flaws surfaced today, including an unpatchable Apple chip exploit and a novel phishing technique.
An unpatchable Boot ROM vulnerability called usbliter8 affects Apple's A12 and A13 chips, giving attackers persistent low-level access that even Apple can't fix.
Phishers are using IPv4-mapped IPv6 addresses to bypass security controls that extract domains via regex, targeting a Belgian bank with a novel URL trick.
Apple patched a high-severity eavesdropping bug in Beats Studio Buds after a 12-month disclosure, with researchers noting the attack chain could also leak call history and contacts.
Also today5
10 signs that someone is monitoring or accessing your accounts - how to stop themwww.zdnet.com
EXPLOITATION OF MODEL CONTEXT PROTOCOL IN AGENTIC AI DEPLOYMENTSwww.hendryadrian.com
License Plate Cameras Will Soon Track Phones, Wearables, Infotainment, and Even Your Petsshare.google
Cybercriminals abused GitHub, YouTube and VirusTotal to push crypto-stealing malwarewww.helpnetsecurity.com
NVD - CVE-2026-56073nvd.nist.gov
More roundups that day
space industry roundupSpaceX's post-IPO identity crisis deepens
publishing roundupAI controversy shakes publishing world

psychology roundupThe psychology of over-explaining and stigma today
entrepreneurship roundupCashing out and focusing up
history roundupJuneteenth, dictators' chefs, rare cauldron
photography roundup