Issue #205 - June 29, 2026
- Jun 29
- 2 min read
FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks
Source: SecurityWeek
Researchers linked the FortiBleed credential-harvesting campaign to INC and Lynx ransomware activity. SOCRadar reported scanning against thousands of FortiGate portals, hundreds of successful administrative compromises, and at least 12 ransomware deployments, showing how stolen edge-device credentials can quickly become enterprise-wide extortion access.
China-Linked Group Targets Southeast Asia Critical Systems
Source: Dark Reading
A China-linked threat group tracked as CL-STA-1062 has expanded from Taiwanese web-hosting targets into Southeast Asian critical infrastructure. Researchers said the group compromised electricity, water, government, and military-related organizations and deployed a new backdoor called TinyRCT for persistence, command execution, and possible intelligence collection.
Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters
Source: The Hacker News
Researchers warned that Argo CD's repo-server component has an unpatched flaw that may allow unauthenticated command execution when the internal service is reachable. Because Argo CD builds Kubernetes deployment manifests, exploitation could enable cluster takeover, making segmentation and internal service access controls especially urgent.
Hackers target Microsoft 365 accounts with 81 million login attempts
Source: BleepingComputer
A large password-spraying campaign generated more than 81 million login attempts against Microsoft 365 accounts over two weeks. Attackers used valid username-password pairs from prior breaches and attempted Azure CLI authentication through ROPC, exposing gaps in conditional access policies and MFA enforcement.
Aflac Japan: Hack Detected Last Week Affects Nearly 4.4M
Source: Data Breach Today
Aflac's Japanese subsidiary disclosed that a June hacking incident affected nearly 4.4 million customers and agents. The exposed information may include policy details, personal data, and bank account information, with certain services suspended while the insurer investigates the cause, scope, and remediation steps.



