These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
A large-scale credential harvesting campaign dubbed FortiBleed has exposed verified administrator passwords for approximately 75,000 Fortinet FortiGate firewalls, including devices operated by government agencies, critical infrastructure providers, and major enterprises across 194 countries. The campaign, traced to a Russian-speaking threat group, did not exploit a new vulnerability. Attackers systematically harvested and cracked SSL VPN authentication hashes from internet-facing devices, many of which were fully patched.
Microsoft has confirmed an agreement to provision AWS infrastructure for GitHub workloads, after GitHub recorded nine service incidents in May 2026 and availability dropped to roughly 88 percent in June. The move reflects a structural shift: AI coding tools have driven GitHub’s weekly commit volume to 275 million and its Actions compute minutes to 2.1 billion per week, growth that Microsoft’s own Azure infrastructure was not provisioned to absorb. The decision is the most public acknowledgement to date that no single cloud provider, including one’s own, can reliably self-contain the infrastructure demands of a major AI-driven platform.
A coordinated campaign on the JetBrains Marketplace placed 15 plugins disguised as AI coding assistants that silently exfiltrate AI provider API keys to an attacker-controlled server. The campaign ran from October 2025 through at least 10 June 2026, accumulated over 70,000 installs across seven vendor accounts, and targeted credentials for OpenAI, DeepSeek, and other AI services. Developers who installed any of the flagged plugins should rotate all AI provider keys immediately.
Trend Micro researchers have documented QLNX, a previously undisclosed Linux implant designed specifically to infiltrate developer workstations and DevOps pipelines. The malware combines a userland LD_PRELOAD rootkit with a kernel-level eBPF component to evade detection, then harvests credentials from more than 20 high-value configuration files including AWS, Kubernetes, GitHub, Docker, npm, PyPI, Vault and Terraform. Only four security tools detected the binary at the time of publication.
At AWS Summit New York 2026, Amazon unveiled the three pillars of its agentic AI infrastructure: Amazon Bedrock AgentCore, a seven-service runtime for deploying enterprise AI agents securely; Kiro, a spec-driven agentic IDE that replaces Amazon Q Developer; and Amazon Quick, the enterprise answer agent replacing Q Business. Together they represent AWS’s most complete statement yet on how it expects organisations to build, run, and govern AI agents in production.
A security researcher known as Nightmare Eclipse has published a new zero-day exploit named GreatXML that bypasses BitLocker encryption on Windows systems by abusing the Windows Recovery Environment and an unattend.xml configuration file left behind by Windows Defender Offline Scan. The exploit requires no login, works on fully patched Windows 11 and Windows Server 2025, and was released publicly with no coordinated disclosure to Microsoft. It is the second zero-day from the same researcher in three days.
The ShinyHunters extortion group has claimed responsibility for a breach of the Council of Europe, alleging the theft of 297 GB of data covering more than 429,000 files and payslips from approximately 10,000 current and former employees. The claimed data includes salary records, bank account details, tax and social security information, CVs, and internal HR documents from the Secretariat, Parliamentary Assembly, and the European Directorate for the Quality of Medicines. The Council of Europe has confirmed it is investigating.
Google Cloud’s H1 2026 Threat Horizons report marks a structural shift in cloud attacks: for the first time, exploiting software vulnerabilities (44.5%) has overtaken credential theft (27.2%) as the primary method attackers use to gain initial access to cloud environments. Worse, threat actors now weaponise newly disclosed cloud vulnerabilities within 48 hours of public disclosure, collapsing the window that patch management processes were designed for.
Security researcher Justin O’Leary disclosed that a critical privilege escalation vulnerability in Azure Backup for AKS allows a user with only the Azure-level ‘Backup Contributor’ role and zero Kubernetes permissions to obtain cluster-admin access on any AKS cluster. Microsoft rejected the vulnerability report, blocked CVE assignment through MITRE, and then silently deployed a fix while publicly stating that ’no product changes were made.’ The vulnerability is tracked as VU#284781 by CERT/CC.
CERT-EU has confirmed that the European Commission’s March 2026 AWS cloud breach, which resulted in 350 GB of stolen data published by ShinyHunters, began with CVE-2026-33634, a supply chain compromise of the Trivy open-source vulnerability scanner. The threat actor group TeamPCP tampered with Trivy’s GitHub Actions workflow, injecting a credential-stealing payload into over 10,000 CI/CD pipelines worldwide. Any organisation whose pipelines used Trivy between 19 and 24 March 2026 should treat all secrets harvested during that window as compromised.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.