CYBER_THREATCAST
$ briefing --date=

CYBER THREATCAST

CYBER THREAT INTELLIGENCE BRIEFING

Sunday, June 21, 2026|MORNING EDITION|08:03 TR (05:03 UTC)|119 Signals|15 Sectors
ROUNDTABLE ACTIVE7 agents · 13 messages · 19mView →
CISA warned that attackers are actively using a leaked dataset tied to about 74,000 Fortinet devices to break into exposed FortiGate firewalls and VPN gateways, while a separate wave of active exploitation hit the Gravity SMTP WordPress plugin, where CVE-2026-4020 exposed API keys and OAuth tokens and drew more than 17 million blocked attempts, according to Wordfence. The day’s most urgent picture is blunt: stolen credentials, exposed edge devices, and internet-facing software flaws are still turning straight into access.
The Fortinet case stands out because it joins old exposure to current intrusion activity at scale. CISA says the leaked cache includes plaintext usernames and passwords for FortiOS SSL-VPN systems, and reporting tied the campaign to billions of login attempts and full compromise at at least four organizations. That makes this less a leak story than an access-operations story, with attackers moving from harvested credentials to firewall and VPN entry points worldwide.
Crypto incidents supplied the other major concentration of losses. A custom Secret Network Axelar integration flaw let an attacker forge IBC packets and drain about $4.67 million, Hyperbridge was hit by a forged-message flaw that minted 1 billion bridged DOT tokens on Ethereum, and attackers reportedly tricked the Jaredfromsubway MEV bot into approving attacker-controlled addresses and losing about $15 million. The common thread is trust abuse in bridges, contracts, and automated trading logic rather than novel endpoint malware.

Editorial: Recommended Actions

01
PRIORITY
Rotate all credentials on internet-facing Fortinet FortiGate and FortiOS SSL-VPN systems immediately, disable exposed VPN access where possible until reviewed, and hunt for follow-on compromise in Active Directory and affected edge devices. CISA says attackers are actively using a leaked dataset covering roughly 74,000 Fortinet devices, including plaintext usernames and passwords, and reporting ties the campaign to billions of login attempts and full compromises at multiple organizations.
02
PRIORITY
Update the Gravity SMTP WordPress plugin to version 2.1.5 immediately and treat exposed sites as potentially credential-compromised by rotating any API keys or OAuth tokens that may have been stored or revealed in system reports. Threat actors are actively exploiting CVE-2026-4020, an unauthenticated REST API information disclosure flaw, and Wordfence says blocked attempts have already topped 17 million. Any WordPress site running Gravity SMTP is in scope, especially if the plugin exposed plugins, themes, server details, or authentication material.
03
PRIORITY
Upgrade WinRAR on Windows endpoints to version 7.13 or later and warn users that spear-phishing emails may carry malicious RAR archives targeting CVE-2025-8088. Reporting says organized threat actors are exploiting this path traversal flaw in the wild, with archive attachments used as the delivery mechanism. Organizations that still allow older WinRAR versions on user workstations, jump hosts, or shared admin systems should prioritize those systems first.
04
PRIORITY
Review every custom ICS-20 and CW20-ICS20 token contract modification before redeployment, and suspend trust in third-party bridge integrations that removed source-channel or escrow-balance checks until code and message-validation logic are reverified. Technical reporting says unsafe changes in a Secret Network Axelar integration let an attacker forge packets through a fake Cosmos chain and drain about $4.67 million in escrowed assets. Teams operating Cosmos-linked bridges or derived token contracts should assume bespoke logic around IBC packet receive paths is a high-risk area.
05
PRIORITY
Pause or tightly constrain exposure to bridged DOT on Ethereum until message validation and admin-control paths are independently reviewed, and verify that proof handling cannot be replayed or separated from the originating request. Reporting says a forged-message flaw gave an attacker admin control of the Polkadot token contract on Ethereum and enabled minting of 1 billion bridged DOT tokens. The impact was limited to bridged DOT on Ethereum rather than native Polkadot, so exchanges, custodians, and DeFi operators handling the bridged asset should focus controls there first.
ROUNDTABLE
Expert Panel Discussion
7 AI experts analyzed this briefing across 3 turns of structured debate
7Agents13Messages19mDuration

Field Signals

Real-time intelligence from X/Twitter
$ scanning feeds_

Sector Intelligence

Cyber Threatcast is generated by an autonomous AI intelligence pipeline. All assessments are algorithmically derived.

Published by halilozturkci.com