Weekly review

ThreatNoir Weekend Brief — June 20

2026-06-20Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — June 20, 2026

The security landscape continues to shift as threat actors exploit unpatched vulnerabilities in widely deployed software, credential theft campaigns target critical infrastructure, and data breaches expose millions of records. Today's review covers active exploitation campaigns, regulatory enforcement actions, and large-scale compromises affecting organizations across multiple sectors.

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

Threat actors are actively exploiting a recently patched security flaw in Gravity SMTP, a WordPress plugin installed on approximately 100,000 websites. The vulnerability, tracked as CVE-2026-4020 with a CVSS score of 5.3, is classified as a medium-severity information disclosure flaw that allows unauthenticated attackers to extract sensitive data including configuration information, API keys, secrets, and OAuth tokens. Security researchers have identified multiple IP addresses associated with exploitation attempts, indicating coordinated attack activity targeting vulnerable installations.

Source: Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

Hungarian Data Protection Authority Issues GDPR Enforcement Decision

The National Authority for Data Protection and Freedom of Information in Hungary (NAIH) has issued a formal decision regarding unlawful disclosure of personal data. The case, numbered 4094-1/2026, addresses a breach of GDPR requirements where a family address was improperly disclosed in an official summons document. This enforcement action underscores regulatory scrutiny of data handling practices by government authorities and the continued application of privacy standards across all institutional actors.

Source: NAIH (Hungary) - 4094-1/2026

Hackers Claim to Leak Stolen Madison Square Garden Data

Threat actors have announced the theft and release of customer data from Madison Square Garden, marking another significant breach affecting a major entertainment venue. The incident represents a growing trend of attacks targeting high-profile organizations and their customer databases. This breach coincides with broader security concerns including unauthorized surveillance technologies deployed by businesses and shifting geopolitical decisions regarding data analytics partnerships.

Source: Hackers Claim to Leak Stolen Madison Square Garden Data

FortiBleed: 86,000 Fortinet Device Credentials Compromised

A large-scale credential theft campaign designated FortiBleed has compromised approximately 86,000 credentials from Fortinet firewalls and VPN devices, affecting roughly half of all internet-accessible Fortinet infrastructure. This campaign represents a critical threat to enterprise network security, as Fortinet devices serve as primary perimeter defenses for organizations worldwide. The scale of this compromise suggests systematic exploitation of vulnerable SSL VPN implementations and poses significant risk for lateral movement and network infiltration.

Source: FortiBleed: 86,000 Fortinet Device Credentials Compromised

The afternoon's threat intelligence reveals an active exploitation environment where unpatched software vulnerabilities and credential theft campaigns present immediate risks to organizations. Security teams should prioritize patch deployment for the Gravity SMTP plugin, review Fortinet device security postures, and monitor for indicators of compromise associated with these campaigns.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
CVE1
IP Address10
  • 45.148.10.95
    IP address used in exploit attempts
  • 193.32.162.60
    IP address used in exploit attempts
  • 176.65.148.139
    IP address used in exploit attempts
  • 173.199.90.188
    IP address used in exploit attempts
  • 45.148.10.120
    IP address used in exploit attempts
  • 185.8.107.155
    IP address used in exploit attempts
  • 185.8.106.37
    IP address used in exploit attempts
  • 185.8.106.92
    IP address used in exploit attempts
  • 185.8.106.145
    IP address used in exploit attempts
  • 176.65.148.30
    IP address used in exploit attempts