Security Brief Daily

Jun 18, 2026 · #84


Listen Later

Episode 84

Security Brief Daily | 18 Jun 2026

In This Episode
  • FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.Bleeping Computer
    Update: Added Fortinet's statement to the end of the article. A newly discovered data leak dubbed "FortiBleed" has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide. The exposed data was first...
  • CISA orders feds to patch max severity Joomla plugin flaw by FridayBleeping Computer
    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a maximum-severity flaw in the Widget Factory Joomla Content Editor (JCE) plugin that is being actively exploited in the wild. Tracked as CVE-2026-48907 , this vulnerability...
  • Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal CommentsThe Hacker News
    An unknown threat actor has been observed leveraging paid or promoted posts on legitimate news websites to drum up buzz for their warez, according to new findings from Check Point Research. The threat actor also has at their disposal a dedicated WordPress phishing page that...
  • Kodak confirms data breach claimed by ShinyHunters extortion gangBleeping Computer
    Kodak has confirmed that it's working with external cybersecurity experts to investigate a security breach after hackers gained access to some of the company's data. Founded in 1880 as the Eastman Kodak Company and headquartered in Rochester, New York, Kodak has 79,000...
  • Steam Workshop abused to spread malware via Wallpaper Engine appBleeping Computer
    Threat actors are abusing Steam Workshop, Valve's community hub for downloading game-related content, to push various malware hidden in wallpaper packages. Infected wallpapers can lead to hijacking Steam accounts, compromising the system with a backdoor, or running...
  • CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code ExecutionThe Hacker News
    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The...
  • Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went OfflineThe Hacker News
    A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials. Ordinary stuff, until one move near the end. Before his command-and-control server went dark, he installed OpenSSH and Tailscale on a...
  • New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet FundsThe Hacker News
    Security researchers at Zimperium's zLabs have documented a new Android banking trojan, Rokarolla, that targets 217 banking and cryptocurrency apps and packs 137 remote commands. Together, they give an operator near-total control of an infected phone: it lifts lock-screen...
  • Security Brief Daily is an AI-generated cybersecurity news podcast. Always verify critical information with primary sources.

    ...more
    View all episodesView all episodes
    Download on the App Store

    Security Brief DailyBy Security Brief Daily