Morning Review in IT Security — June 20, 2026
The security landscape continues to shift rapidly as researchers expose critical hardware vulnerabilities, law enforcement disrupts major malware operations, and threat actors expand their targeting of enterprise infrastructure. Today's briefing covers unpatchable hardware flaws affecting millions of Apple devices, widespread campaigns against Fortinet equipment, OAuth token theft targeting Salesforce environments, and significant progress in dismantling notorious malware distribution networks.
Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain
Security researchers at Paradigm Shift have published a working exploit called usbliter8 that achieves arbitrary code execution inside the SecureROM of Apple's A12 and A13 chips. The vulnerability exists in code burned directly into silicon at manufacture, making it permanently unfixable through software updates. Affected devices will retain this flaw throughout their operational lifetime. Source: Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain
The exploit does not function as a remote attack vector and requires physical or local access to the target device. This discovery underscores the lasting security implications of hardware-level vulnerabilities and the limitations of software-only remediation strategies for silicon-based flaws.
CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
The U.S. Cybersecurity and Infrastructure Security Agency has issued an urgent warning to Fortinet customers operating FortiGate appliances following a sweeping campaign targeting thousands of internet-accessible devices. The campaign, dubbed FortiBleed and attributed to Russian-speaking threat actors, has compromised 86,644 devices. Source: CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
The scale of this compromise represents a significant supply chain and infrastructure risk, with malicious actors leveraging the widespread deployment of FortiGate appliances in critical network environments.
Klue OAuth Breach Victim List Grows as Icarus Hackers Claim Attack
Market intelligence platform Klue has publicly confirmed a security incident in which threat actors stole OAuth tokens used to connect to customers' Salesforce environments. The newly identified Icarus extortion group has claimed responsibility for the attack. Source: Klue OAuth breach victim list grows as Icarus hackers claim attack
This breach highlights the risks associated with third-party integrations and the potential for OAuth token theft to provide attackers with direct access to enterprise SaaS platforms without requiring valid user credentials.
Hackers Exploit Info Disclosure Bug in Gravity SMTP WordPress Plugin
Threat actors are actively exploiting an unauthenticated information disclosure vulnerability in the Gravity SMTP WordPress plugin, which is installed on approximately 100,000 websites. The vulnerability, tracked as CVE-2026-4020, allows attackers to extract sensitive information without authentication. Source: Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
The widespread deployment of this plugin combined with the ease of exploitation creates a substantial attack surface for credential harvesting and lateral movement within affected WordPress installations.
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
The Gentlemen ransomware-as-a-service operation actively develops and distributes a sophisticated suite of endpoint detection and response killers to its affiliates. The GentleKiller framework, which serves as the centerpiece of this EDR-termination arsenal, targets approximately 400 security processes to disable system defenses before ransomware deployment. Source: The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
The operation maintains additional EDR-killing tools including HavocKiller, HexKiller, and ThrottleBlood, demonstrating a mature and well-resourced approach to defeating enterprise security infrastructure during ransomware attacks.
AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
Microsoft researchers have disclosed an exploit chain named AutoJack that converts an AI browsing agent into a delivery mechanism for remote code execution. By directing the agent to load an attacker-controlled web page, the page's JavaScript can interact with a privileged local service and spawn processes on the host system without requiring credentials or user interaction. Source: AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
This vulnerability represents an emerging threat vector as organizations increasingly deploy AI agents for automated browsing and task execution, creating new attack surfaces that bypass traditional authentication mechanisms.
In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum
Additional significant developments include Apple patching an eavesdropping vulnerability in Beats products, the Department of Transportation closing its investigation into Delta's CrowdStrike incident, and discovery of an Android TV botnet linked to an Israeli firm. An unpatched GCP Config Connector flaw has been identified as enabling account takeover, while the Velvet Ant threat actor maintained stealth operations for a decade. Source: In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum
These developments underscore the breadth of security challenges spanning consumer devices, cloud infrastructure, and third-party integrations across multiple technology ecosystems.
Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites
Dutch law enforcement, coordinating with authorities from Canada, Germany, and the United States, has successfully disrupted malicious infrastructure associated with SocGholish and remediated nearly 15,000 infected WordPress websites. The operation removed access to systems previously compromised by cybercriminals. Source: Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites
The SocGholish ecosystem distributed multiple malware families including AsyncRAT, FakeUpdates, Gholoader, LockBit, and NetSupport RAT, demonstrating how a single malware distribution network served as a supply chain for numerous threat actors and ransomware operations.
Today's threat landscape reflects both the persistent challenges of hardware-level vulnerabilities and the ongoing effectiveness of international law enforcement operations in disrupting large-scale malware distribution networks. Organizations must prioritize patching vulnerable plugins, securing OAuth implementations, and monitoring for signs of EDR-killing tools within their environments.