The UK National Cyber Security Centre released formal guidance for Fortinet customers today in response to the FortiBleed campaign, as additional confirmed detail emerged about the scale and mechanism of the operation. The Infosecurity Magazine report published today, citing NCSC and Hudson Rock data, confirmed that the credential database contains verified working logins for organisations including Oracle, Spotify, Toyota, and AT&T, and spans over 21,000 unique domains across 194 countries. Kevin Beaumont and Hudson Rock independently verified that sampled logins from the database are real and current, covering approximately half of all internet-facing Fortinet firewalls globally.
SOCRadar’s detailed analysis of the operation confirmed a self-sustaining mechanism at its core. Once attackers successfully compromise a FortiGate device, that device is configured to monitor SSL VPN traffic passing through it and capture authentication credentials from employees connecting to the network via VPN. Those captured credentials are automatically fed back into the central scanning and authentication testing operation, allowing the campaign to grow through the compromised devices themselves rather than requiring the attacker to find entirely new targets. The operation has been running since at least February 2026 and continued to add new compromised devices as of the most recent reporting.
Security researcher Bob Diachenko attributed the campaign to a Russian-speaking threat actor based on infrastructure and operational patterns. At least four organisations have been fully compromised based on his investigation. The NCSC’s guidance published today specifically addresses credential rotation alongside patching as essential steps, reflecting the self-feeding dynamic.
- Apply the latest Fortinet firmware updates to all internet-accessible FortiGate appliances. Patching closes the active exploitation paths but does not address credentials already compromised.
- Rotate all FortiGate administrator credentials and VPN user credentials immediately after patching. Credentials captured during the compromise window remain valid until changed.
- Audit all FortiGate administrator accounts for any accounts created or modified during the compromise window. Attackers may have established persistence through new accounts.
- Rename or disable the default admin account and any built-in Fortinet system accounts, as these remain the primary vector for the scanning phase of the campaign.
- Monitor FortiGate authentication logs for successful logins from unexpected IP addresses or at unexpected times, which may indicate use of harvested credentials.
Revenue intelligence platform Gong disclosed on June 20 that it disabled its Klue Battlecards integration after discovering that attackers had exploited the compromised Klue OAuth token collection mechanism to access its Salesforce environment. Gong confirmed the data accessed was limited to internal licensed user information including user names, business titles, and email addresses, and that call recordings and customer transcripts were not reached.
The Icarus extortion group, which Huntress attributed responsibility for the original Klue breach in Issue 67, added Klue to its Tor-based leak site over the weekend. The group claimed responsibility for the attack and threatened to publish data stolen from affected organisations’ Salesforce instances unless negotiations begin. Icarus stated June 22 as the deadline for the data to be published or negotiations to commence.
SecurityWeek reported today that multiple additional cybersecurity and technology firms are assessing their exposure after the Gong disclosure, as Klue’s customer list spans a broad range of enterprise organisations that use it for competitive intelligence integrated with their CRM data. The full scope of affected organisations has not yet been confirmed publicly.
- Revoke and rotate all OAuth tokens, refresh tokens, and client secrets associated with the Klue Battlecards integration in your Salesforce environment if not already done.
- Audit Salesforce API logs for the period June 11 to 17 for unusual query volumes from Klue service accounts, Python-urllib user-agent strings, and bulk record query patterns.
- If you have not yet received a notification from Klue, do not interpret the absence of contact as confirmation you were unaffected. Proactively audit your Salesforce connected apps and OAuth grant list for the Klue integration and its associated service accounts.
The UK National Cyber Security Centre published guidance today on the security implications of vibe coding, the practice of using AI models to generate software from natural-language prompts with minimal developer review of the output. The agency says AI-generated code can introduce security flaws and create systems that are difficult to understand or maintain, even when the code appears functional and passes basic tests.
The NCSC draws a distinction between low-risk and experimental use cases, which it considers acceptable, and production systems where security matters, for which it says AI-generated output must be thoroughly reviewed, tested, and understood by developers before deployment. The agency specifically warns against deploying code that the development team does not understand, noting that this creates audit and incident response problems that extend beyond the initial security risk.
The guidance notes that AI models are evolving and that calibrated trust may be appropriate as reliability improves, but explicitly states that developers should base their current practices on today’s model capabilities rather than anticipated future improvement. The NCSC positions the guidance as practical advice for developers navigating a genuinely novel situation, acknowledging the productivity benefits of AI coding assistance while being direct about the security risks of using it without adequate review discipline.
- Apply the same code review standards to AI-generated code as to any other untrusted contribution. Do not merge AI-generated code that the reviewing developer does not understand.
- Restrict vibe coding and fully AI-generated code to low-risk and experimental contexts. Production systems where security matters require human review of all code before deployment.
- Include AI-generated code in static analysis, dependency scanning, and security testing pipelines. The fact that an AI generated the code does not exempt it from standard security tooling.
- Federal cybersecurity advisories
- Law enforcement threat bulletins
- National vulnerability databases
- Major vendor security advisories
- Cross-referenced for relevance and corroboration
CyberSip aggregates cybersecurity information from publicly available sources for informational purposes only. CyberSip does not provide legal, technical, incident response, or compliance advice, and makes no guarantee regarding completeness, accuracy, or timeliness. Organizations should validate all findings within their own environments and consult qualified professionals as appropriate. Original advisories, remediation guidance, and technical details remain with the referenced source organizations. Items remain active for no more than 7 days from publication unless materially updated.