- FortiBleedName of the credential theft campaign
ThreatNoir Afternoon Brief — June 19
Afternoon Review in IT Security — June 19, 2026
The threat landscape remains active on this afternoon, with critical vulnerabilities demanding immediate action, large-scale credential compromises affecting major infrastructure vendors, and opportunistic campaigns targeting high-profile sporting events. Organizations face mounting pressure to patch systems and secure exposed credentials before attackers expand their foothold.
FortiBleed: 86,000 Fortinet Device Credentials Compromised
A massive credential theft campaign has targeted approximately half of all internet-accessible Fortinet firewalls and VPNs, resulting in the compromise of roughly 86,000 device credentials. The FortiBleed attack represents a significant threat to organizational perimeter security, as compromised firewall and VPN credentials provide attackers with direct access to protected networks. Source: FortiBleed: 86,000 Fortinet Device Credentials Compromised
CISA: Splunk Enterprise Flaw Actively Exploited, Patch by Sunday
The Cybersecurity and Infrastructure Security Agency has issued an urgent directive to U.S. federal agencies regarding CVE-2026-20253, a critical vulnerability in Splunk Enterprise that is actively being exploited in the wild. CISA has mandated that all federal agencies apply patches by Sunday to prevent further compromise of their systems. The active exploitation status elevates this vulnerability to critical priority, making immediate patching essential across government and critical infrastructure sectors. Source: CISA: Splunk Enterprise flaw actively exploited, patch by Sunday
CryptoBandits Malware Doubles as a Backdoor, Abuses Tor
Security researchers have identified CryptoBandits, a sophisticated malware variant that combines cryptocurrency theft capabilities with remote code execution functionality through backdoor mechanisms. The malware leverages a local SOCKS5 proxy for traffic routing and abuses the Tor network to obfuscate its command and control communications, enabling attackers to maintain persistent access while stealing cryptocurrency assets. This dual-purpose approach makes CryptoBandits a particularly dangerous threat to organizations handling digital assets. Source: CryptoBandits Malware Doubles as a Backdoor, Abuses Tor
FIFA World Cup 2026: Hackers Target Football Fans With Fake Tickets Sites
Cybersecurity experts have identified active hacking networks deploying fake ticket and hotel booking websites targeting FIFA World Cup 2026 fans. These scam operations utilize cloned legitimate websites, fake ticketing domains, and integrated live chat features to deceive users into providing payment information and personal data. Notable malicious domains include cn-web-fifacwc.com, fifa.monster, fifaworldcup2026cityhotels.com, tbpay.uk, worldcup2026ticket.shop, ww-fifa.com, and zone-2026fifa.com. The campaign demonstrates how threat actors exploit major sporting events to conduct large-scale fraud operations against unsuspecting consumers. Source: FIFA World Cup 2026: Hackers Target Football Fans With Fake Tickets Sites
As the afternoon progresses, organizations must prioritize patching the Splunk Enterprise vulnerability, rotating compromised Fortinet credentials, and maintaining vigilance against emerging malware families. End users should exercise heightened caution when purchasing World Cup tickets and accommodations, verifying domain authenticity before providing sensitive information.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Critical Splunk Enterprise vulnerability
- CryptoBanditsName of the malware family
fifa.monsterCloned FIFA website used for tracking visitors and follow-up spam.tbpay.ukUnauthorized payment control panel used by threat actors.cn-web-fifacwc.comFake gambling platform link used in FIFA World Cup scam.ww-fifa.comRealistic online checkout page for fake ticket purchases.worldcup2026ticket.shopFake ticket shopping cart domain used in FIFA World Cup scam.zone-2026fifa.comFake gambling platform link used in FIFA World Cup scam.fifaworldcup2026cityhotels.comFake hotel booking network domain used in FIFA World Cup scam.