DigitalXRAID

Threat Pulse – June 2026

Each month, DigitalXRAID’s Security Operations Centre (SOC) analysts share the top threats affecting businesses globally. Take action to protect your organisation against these prolific threats.

If you’ve been affected by any of these threats, we’re here to help. You can call our Cyber Emergency line any time of the day or night for help with active cyberattacks.

DigitalXRAID’s SOC analysts constantly monitor for zero-day threats and update our signature databases using the most comprehensive Threat Intelligence and Open Threat Exchange databases available worldwide.

Cyber Incidents in June

Salesforce Customers (Recorded Future, Huntress, LastPass, HackerOne and Others) – Klue OAuth Supply Chain Attack

What happened:

A wave of Salesforce data thefts came to light on 17 June after Salesforce disabled its integration with Klue’s Battlecards application following a breach at the app vendor. Cybersecurity vendor Huntress was the first company to publicly acknowledge that its Salesforce data had been compromised, and an extortion group calling itself Icarus claimed responsibility and said more victims would follow.

Who was behind it:

The attacks were claimed by an extortion group tracked as Icarus, which gained access through stolen OAuth tokens belonging to Klue, a market intelligence and sales enablement vendor with integrations across many corporate Salesforce environments.

How the attack worked:

Rather than attacking Salesforce directly, the group compromised Klue and used its OAuth tokens to reach the Salesforce instances of every company that had connected the Klue app, including downstream integrations such as Gong. Because OAuth tokens grant trusted, ongoing access, the attackers did not need to phish individual employees once the token itself was in hand.

Scale of the damage:

By late June, disclosures had been made by LastPass, HackerOne, Recorded Future, Jamf, Snyk, OneTrust, Insurity, Tanium and Sprout Social, among others. Gong confirmed that internal licensed user data, including usernames, job titles and emails, had been accessed for a subset of customers who used the Klue integration. Icarus began publishing victim data on its leak site after a deadline passed, with six Klue customers listed at the time of writing.

Real world impact:

The breach shows how a single compromised application vendor can cascade into dozens of otherwise well-defended organisations through trusted OAuth connections. Several affected companies, including Huntress, warned that the primary risk was not the data itself but the convincing, business-specific phishing it now enables against customers and partners.

Response and recovery:

Affected organisations suspended access to Klue, rotated exposed API tokens and launched investigations. LastPass confirmed its core products, services and customer vaults remained secure, and HackerOne said its data segmentation controls meant no customer vulnerability data was accessible through the compromised system.

Remediation guidance:

Maintain an inventory of every third-party application with an OAuth connection into core platforms such as Salesforce, and review the scope of access each one holds.

Enforce least-privilege OAuth scopes and rotate or revoke tokens for any app vendor that experiences a security incident, even where the relationship feels low risk.

Verify any incident-related communication through a known channel before transferring funds, sharing credentials or actioning urgent requests that reference a real vendor relationship.

Review Salesforce and other SaaS instances for inadvertently stored secrets, API keys or tokens left in case data, attachments or notes fields.

FortiBleed – Global Fortinet Firewall Credential Harvesting Campaign

What happened:

Security researchers identified a large-scale, ongoing credential harvesting campaign, dubbed FortiBleed, affecting FortiGate firewalls and VPN gateways. By the time CISA and the UK National Cyber Security Centre issued advisories in mid to late June, the confirmed device count had climbed past 86,000 across 194 countries.

Who was behind it:

Researchers at SOCRadar and other firms assessed the operation as most likely run by a Russian-speaking, financially motivated initial access broker, with later attribution pointing to ties with the Lynx and INC ransomware groups. The campaign has been running since at least February 2026.

How the attack worked:

Rather than exploiting a new software vulnerability, the attackers assembled usernames and passwords from earlier Fortinet-related breaches and infostealer logs, then automatically tested them around the clock against internet-facing FortiGate devices. Once inside a device, it was turned into a passive listening post, sniffing genuine SSL VPN traffic to harvest yet more credentials, which were fed back into the scanner to compromise further devices.

Scale of the damage:

The attacker built a verified database of working credentials for more than 86,000 devices, including Kerberos, NTLM and RADIUS material, organised by sector, country and revenue. Confirmed victims span government, telecommunications, healthcare, education, manufacturing and financial services, and include a Turkish NATO-aligned defence contractor that suffered confirmed exfiltration of classified documents.

Real world impact:

The scale means organisations across almost every sector face exposure, regardless of whether they were directly targeted, since credentials can leak silently from devices that appear fully patched and operational. The presence of post-exploitation tunnelling tools previously seen in state-sponsored campaigns suggests the same credential pool is being used for both opportunistic crime and targeted espionage.

Response and recovery:

CISA and the NCSC urged all Fortinet customers to terminate active sessions, reset every Fortinet VPN and administrative password and review logs for unauthorised access. Fortinet published its own guidance, and several major vendors and government bodies confirmed they were among those affected and took remediation steps.

Remediation guidance:

Rotate all Fortinet VPN and administrative credentials immediately, regardless of whether your organisation is confirmed in the dataset.

Enforce multi-factor authentication on all remote access and administrative interfaces.

Remove FortiGate management interfaces from direct internet exposure wherever possible.

Review authentication and gateway logs for anomalous logins, new accounts or configuration changes, and treat any FortiOS upgrade history as a prompt to check whether passwords were ever rotated after the upgrade.

DentaQuest – Healthcare Benefits Administrator Data Leak

What happened:

ShinyHunters published roughly 234 gigabytes of data stolen from DentaQuest, one of the largest dental and vision benefits administrators in the United States, after extortion negotiations failed. DentaQuest confirmed on 2 June that a portion of its network had suffered unauthorised access.

Who was behind it:

The ShinyHunters extortion group claimed responsibility, having added DentaQuest to its dark web leak site in May before publishing the data when the company did not meet its demands.

How the attack worked:

DentaQuest has not disclosed the precise initial access vector, but the breach fits a pattern seen repeatedly across the group’s 2026 campaign, in which large volumes of data are stolen first and encryption is skipped entirely in favour of a pay or leak extortion model.

Scale of the damage:

Have I Been Pwned confirmed more than 2.5 million unique email addresses in the dataset, alongside names, dates of birth, addresses, phone numbers, genders, government identification numbers and health insurance information. A large share of the data appeared in healthcare enrolment files, with some records containing Medicaid identification numbers.

Real world impact:

A large proportion of DentaQuest’s membership is covered through Medicaid and similar government programmes, meaning many of the affected individuals are children, low income families and elderly people who are typically less able to monitor for and respond to identity fraud. The combination of identity data with health insurance and government identifiers creates a long-tailed risk of medical identity theft and benefits fraud.

Response and recovery:

DentaQuest said it took immediate steps to contain the incident, engaged forensic investigators and continued to serve customers with limited disruption. As of early June the company had not yet completed notifications to the relevant health authorities, drawing scrutiny over its compliance with breach notification timelines.

Remediation guidance:

Treat dental, vision and other benefits administrators as holders of protected health information in their own right, and require evidence of their security controls in any contract.

Brief members and staff to expect convincing phishing referencing real coverage, claims or Medicaid details, and to verify any unexpected contact through an official channel.

Where your organisation relies on a third-party benefits administrator, confirm independently what your own notification obligations are if that vendor is breached.

Apply strict access controls and monitoring to any system holding enrolment files or government identification numbers, and minimise retention wherever possible.

FIFA – World Cup Broadcast and Match Systems Access Control Failure

What happened:

An ethical hacker discovered on 14 June that FIFA’s Microsoft Entra environment had no effective access controls separating a basic agent registration account from the organisation’s core systems, including the live production platform controlling World Cup television broadcasts worldwide.

Who was behind it:

The flaw was found and responsibly disclosed by a security researcher known as BobDaHacker, who registered as a football agent through FIFA’s public platform and then tested the boundaries of the account it created.

How the attack worked:

FIFA’s frontend correctly denied the account access and displayed an access denied message, but the backend API behind that frontend had no equivalent server-side check, and served up full access regardless. This client side only authorisation pattern allowed the same unprivileged account to reach FIFA’s streaming management platform, match management system, commentary information system and a developer environment containing files on revenue and player transfers.

Scale of the damage:

Had the access been used maliciously, an attacker could have blacked out any live match for global broadcast audiences, replaced the feed with arbitrary video, altered match scores or start times in real time, or manipulated what commentators saw on screen. No malicious exploitation was confirmed; the issue was found and reported by a researcher.

Real world impact:

The case is a stark illustration of how a single missing server-side check on a low-privilege account can expose systems with global reach and real-world consequences, in this instance the live broadcast of the world’s most watched sporting event. The researcher also noted that FIFA had no published vulnerability disclosure process, forcing them to report the issue through CISA and the FBI instead.

Response and recovery:

The vulnerability appeared to be fixed the day after CISA and the FBI were contacted. FIFA did not respond to media requests for comment, and there is no indication the access control gap had been exploited prior to disclosure.

Remediation guidance:

Never rely on frontend or client-side checks alone for authorisation; every API endpoint must enforce its own server-side access control regardless of what the interface displays.

Publish a clear vulnerability disclosure policy and security contact so researchers can report issues quickly rather than escalating through regulators or law enforcement.

Test high-profile or high-reach systems, especially broadcast, control and public-facing platforms, against the specific scenario of a low-privilege or newly created account attempting to reach administrative functions.

Run a bug bounty or responsible disclosure programme ahead of any major public event, when the cost of a live incident is at its highest.

Nation-State Targeting of Water Systems – Iran, Russia and China

What happened:

Threat intelligence provider DomainTools published research on 25 June detailing a sustained pattern of nation-state targeting of water treatment and distribution systems dating back to 2024, attributed to state-linked actors associated with Iran, Russia and China.

Who was behind it:

The research pointed to multiple state-aligned groups rather than a single actor, with activity consistent with known Iranian, Russian and Chinese cyber operations against water infrastructure in several countries.

How the attack worked:

The researchers found that the entry points were rarely sophisticated. Billing systems, customer portals, GIS repositories, vendor remote access, identity systems, backups and SCADA-adjacent servers were reached through exposed human-machine interfaces and programmable logic controllers, weak or default credentials, exposed remote access tools, shared accounts and poor segmentation between operational technology and IT.

Scale of the damage:

The research did not point to a single mass-casualty event, noting that most modern water systems retain safeguards that prevent contaminated water from reaching the public even where a control system is compromised. The concern is the volume and persistence of access being obtained, treated by the researchers as evidence of intent and reconnaissance rather than isolated incidents.

Real world impact:

Even where a water sector cyber incident does not cause direct physical harm, it demonstrates that nation-state actors can and do reach the operational core of critical infrastructure using straightforward, well understood weaknesses, and that criminal or unattributed intrusions into the same systems should be treated as live proof of the same exposure.

Response and recovery:

The research has been shared with water utilities and government partners, and the recommendation across the sector is to assume that any internet-reachable operational technology has already been probed, rather than to wait for a confirmed incident before acting.

Remediation guidance:

Remove direct internet exposure from human-machine interfaces, programmable logic controllers and any other operational technology component.

Eliminate default, shared and long-lived credentials on operational technology, and enforce unique, regularly rotated access for every account.

Segment operational technology from corporate IT and from billing, customer portal and other business systems that do not need direct access to control infrastructure.

Treat any breach of a billing system, customer portal or vendor access path as a potential precursor to operational technology access, not an isolated IT issue.

Talk to the team to see how you can start protecting your business against cyberattacks today.

Protect Your Business & Your Reputation.

With a continued focus on security, you can rest assured that breaches and exploits won't be holding you back.

Speak To An Expert

cybersecurity experts
x

Get In Touch

[contact-form-7 id="5" title="Contact Us Form"]
DigitalXRAID
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.