TechLogHub Blog — Page 4 of 22
Insights, guides, and product strategy for builders and product teams.

Microsoft: June 2026 Windows updates break Recycle Bin prompts
Microsoft confirms a bug in the June 2026 Windows updates where the Recycle Bin’s delete confirmation shows internal filenames (e.g., $Rxxxxx.ext) instead of the original names for permanently deleted items; the Recycle Bin and restore still display the original name. The issue affects all supported Windows client and server releases after the June 2026 updates (including Windows 11 26H1/25H2/24H2/23H2, Windows 10 22H2 and LTSC editions, and Windows Server 2012–2025). A fix is being developed for a future update, with a temporary workaround available for businesses via Microsoft Support for Business.

CISA: Splunk Enterprise flaw actively exploited, patch by Sunday
US CISA orders federal agencies to patch actively exploited Splunk Enterprise flaw CVE-2026-20253 by Sunday. The vulnerability affects versions 10.2.0–10.2.3 and 10.0.0–10.0.6 and allows unauthenticated remote file operations via a PostgreSQL sidecar endpoint. Splunk issued patches in mid-June amid in-the-wild exploitation, and advises upgrading or disabling the sidecar as a mitigation (the latter may disrupt Edge Processor, OpAmp, or SPL2 pipelines). Shadowserver reports thousands of Splunk instances exposed online, mostly in North America and Europe.

NY man charged after harassing college student with AI-generated nudes
A New York man, Anthony Belford, was indicted on a federal cyberstalking charge for targeting a Georgia college student with an online harassment campaign that used AI-generated nude images and racist messages from spoofed social media profiles. Prosecutors say Belford created fake accounts across Instagram, LinkedIn, Reddit, X, Strava and Yahoo between January and March 2025 to impersonate the victim and send an AI-generated nude image to the victim’s mother. The victim and Belford had attended the same college in 2023–2024, and the harassment continued after the victim transferred to Georgia in August 2024. The case highlights federal laws against sharing intimate images without consent and the broader effort to combat cyberstalking.

CISA warns Fortinet users to secure devices after FortiBleed leak
CISA has urged Fortinet customers to harden devices after the FortiBleed leak exposed credentials for about 74,000 Fortinet devices worldwide, including firewalls and VPN gateways used by major corporations and government entities. The breach appears to involve a Russian-speaking threat group that conducted roughly 1.16 billion credential attempts against FortiGate targets to intercept SSL VPN authentication hashes. Immediate mitigations include terminating all SSL VPN and admin sessions, resetting passwords, enabling phishing-resistant MFA, reviewing logs for signs of unauthorized access, using PBKDF2 hashing for admin credentials, and restricting firewall management interfaces from the public internet. Hudson Rock has released a FortiBleed lookup tool to help organizations check exposure, and authorities note ongoing exploitation of Fortinet vulnerabilities in the wild.

Gentlemen Ransomware Uses Multiple EDR Killers to Disable Defenses
Security researchers report that the Gentlemen ransomware-as-a-service (RaaS) is actively developing a suite of EDR-killing tools to evade defenses, led by GentleKiller, a modular toolkit with at least eight variants that impersonate legitimate security products. These EDR killers use the bring-your-own-vulnerable-driver (BYOVD) technique to escalate privileges and disable security engines in the early stages of an intrusion, enabling encryption and data theft to proceed unimpeded. ESET notes that all GentleKiller variants share common strings, obfuscation techniques, and similar process-killing logic, and target more than 400 processes across roughly 48 security vendors. The operation also employs external tools—HexKiller, ThrottleBlood, HavocKiller—and OxideHarvest, a Rust-based credential stealer developed externally. Gentlemen has previously compromised the Romanian energy provider Oltenia and is linked to a SystemBC botnet with over 1,570 hosts; FortiGate endpoint configurations reportedly guide its targeting.

Nintendo confirms data stolen in WebMD subsidiary cyberattack
Nintendo of America confirms that data from TinyPulse, a WebMD subsidiary used for internal employee surveys, was stolen in a cyberattack, but its systems and customer data were not compromised. Shadowbyt3$ claims to have stolen about 1GB of data and is demanding a $2 million ransom; Nintendo says the breach affected only internal survey data from a small group of employees dating back years and is cooperating with the service provider, with no action required by customers.

USB Worm Spreads Crypto-Stealing Malware via Windows Shortcut Files
A USB worm campaign uses Windows LNK shortcut files on infected USB drives to self-spread and drop clipboard-stealing crypto malware. The malware monitors the clipboard for seed phrases, private keys, and wallet addresses across multiple blockchains and replaces them with attacker-controlled values; it also captures screenshots and transmits data via Tor. Propagation occurs via scheduled tasks that trigger on USB connection, copying itself to new drives and creating additional malicious shortcuts, with remote code execution possible through C2 instructions. Microsoft warns that detection should focus on behavior (wscript.exe/cscript.exe activity, curl/PowerShell/cmd.exe launches) and Tor proxy traffic on localhost:9050.

Klue OAuth Breach Linked to Icarus Salesforce Data Theft Attacks
Klue’s OAuth-based Battlecards integration was exploited by the Icarus extortion group to steal Salesforce CRM data from multiple organizations. Attackers used compromised OAuth tokens to query Salesforce APIs after initial reconnaissance, exfiltrating data over several hours before Salesforce disabled the Klue integration. ReliaQuest and Huntress confirm the incident, noting stolen data includes CRM records, contacts, quotes, and competitive intelligence; Klue has since cut connections to Salesforce and other apps. Organizations are advised to revoke and rotate OAuth tokens, terminate active sessions, and review Salesforce logs for unusual API activity.

5 reasons Microsoft 365 backup isn’t enough for business data protection
A sponsored post by Andy Kerr of Acronis arguing that Microsoft 365 alone does not fully protect business data. It explains the shared-responsibility model and outlines five reasons why 365 backup isn’t enough: (1) ransomware and malicious data loss, (2) retention policies that fall short for compliance, (3) granular recovery is limited and inefficient, (4) phishing and insider threats, and (5) lack of cost-efficient scaling. The piece advocates for a third‑party solution (Acronis) that combines immutable backups, AI-driven threat detection, rapid and granular recovery, long-term retention, and scalable MSP-friendly pricing to fill these gaps.

Police Clean Nearly 15,000 SocGholish-Infected Sites Tied to Evil Corp
Under Operation Endgame, international law enforcement cleaned 14,971 WordPress sites infected by the SocGholish downloader and took 106 servers and domains offline, in a coordinated action by the Netherlands NHCTU, Canada’s RCMP, the US FBI, and Germany’s BKA with Europol/Eurojust support. The operation targets Evil Corp-linked activity and aims to curb further infections by removing backdoors and advising site owners to reset credentials, enable MFA, and keep WordPress up to date. SocGholish has operated since 2017, delivering malware via fake browser updates.

FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices
Fortinet’s FortiGate VPN credentials for about 73,932 firewall URLs across 194 countries were exposed in a data leak dubbed “FortiBleed.” Investigators say the data may come from Fortinet configurations and implicates a Russian-speaking multi-operator group that allegedly conducted billions of credential attempts against FortiGate targets and SQL Server systems. Many affected devices remain online with management interfaces exposed to the internet. Experts urge immediate password rotation, MFA enforcement, and gateway log monitoring; Hudson Rock offers a FortiBleed lookup tool to check exposure.

Why Account Takeovers Are Rising and How to Stop Them
Account takeover attacks are rising as organizations wrestle with managing identities across cloud services, endpoints, and BYOD devices. Attackers leverage credential theft, phishing (including through legitimate services), and MFA fatigue to bypass protections, with credential abuse tied to a significant share of breaches in 2025. The expanding attack surface from unmanaged devices and infostealer malware requires ongoing visibility into device posture and session risk, not just initial login. The post advocates a continuous verification, device-trust approach and highlights Specops Device Trust and password policies as ways to securely bind users to trusted devices, continuously verify posture, and remediate issues without disrupting productivity.

India's Telegram Ban Reaches the UAE: How to Bypass the Block with MTProto Proxy
India has ordered a nationwide Telegram ban until June 22 after investigators say the platform was used to sell leaked NEET exam materials; Telegram claims the move is punishing users and alleges a BGP hijack by Reliance extended the block to the UAE. Experts say the routing disruption is real but the intent is unclear, and Telegram has challenged the order in court. The piece also discusses criticisms of broad platform blocks and offers practical steps to bypass the ban using MTProto proxies, with cautions about proxy trust and security.

Microsoft confirms Office apps launch issues after June updates
Microsoft is investigating reports that post-June 9, 2026 Windows updates prevent certain third‑party apps from launching Microsoft Office programs or opening Office documents. The issue, affecting Word, Excel, PowerPoint, Access and others that use OLE automation, has been observed with apps such as CCH Engagement, Zotero, Workpaper Manager, and dental software like Dentrix and Softdent. Workarounds include opening Office apps or documents directly or applying an enterprise workaround via Microsoft Support for Business; Microsoft says a fix is in progress and will be included in a future Windows update.

CISA orders feds to patch max severity Joomla plugin flaw by Friday
CISA has ordered federal agencies to patch a maximum-severity vulnerability in the Widget Factory Joomla Content Editor (JCE) plugin, CVE-2026-48907, which is being actively exploited to achieve remote code execution via unauthenticated editor-profile creation. The issue requires updating to JCE Pro 2.9.99.6 or later; updating closes the entry point but does not remove existing compromises. To clean compromised sites, back up rogue profiles, apply the patch, delete attacker profiles, change all passwords (admin, database, hosting), and run a full server-side malware scan. CISA added the flaw to the Known Exploited Vulnerabilities Catalog and ordered Federal agencies to patch by the specified Friday under BOD 26-04.

Malicious JetBrains Marketplace Plugins Steal AI API Keys from Developers
Security researchers from Aikido Security warn of a coordinated campaign on the JetBrains Marketplace in which at least 15 malicious plugins—published under seven vendor accounts—steal AI provider API keys entered into their settings. These plugins, advertised as AI coding assistants, code-review tools, and Git utilities, exfiltrate keys to a remote server when users apply them, and some reportedly offer a paid tier that could distribute keys to paying users. The campaign began in October 2025 and was still active as of June 10, 2026, with roughly 70,000 downloads (a figure that can be inflated). The two most downloaded plugins are DeepSeek AI Assist and CodeGPT AI Assistant. JetBrains has not issued a public comment at publication.
.jpg&w=3840&q=75)
New Rokarolla Android malware targets 217 banking, crypto apps
Security researchers have uncovered Rokarolla, a new Android banking trojan that targets 217 banking and cryptocurrency apps. Distributed via fake Chrome or TikTok installers, it acts as a dropper and masquerades as Google Play Protect to gain elevated privileges. Once on a device, Rokarolla uses overlays to steal login credentials and financial data, captures keystrokes, SMS, contacts, and screenshots, and can even keep the device awake or disable protections. Zimperium’s report maps 137 commands and a GitHub repo detailing the botnet’s capabilities, marking Rokarolla as capable of near-complete administrative control.

iRhythm discloses data breach, says hackers stole patient info
iRhythm Holdings disclosed a data breach in which hackers stole patients’ personal and health information from third‑party applications used with its cardiac monitoring service. The attackers contacted the company on June 9 with ransom demands, and iRhythm confirmed data exfiltration on June 10, deeming the incident material due to the data volume. The breach reportedly does not affect iRhythm’s products or medical devices, and no payment card data were involved; the company is investigating with external cybersecurity experts.

Ex-school district employee jailed for hacks on former employer
Former Saydel Community School District IT employee Ezekiel Dean Potter, 34, was sentenced to 21 months in federal prison for a 21-month post-employment cyberattack that disrupted classes, deleted accounts, and cost tens of thousands in remediation; he pleaded guilty in January 2026 and was ordered to pay $59,668.81 restitution and serve three years of supervised release.

phpBB forum fixes auth bypass bug lurking for a decade
A decade‑old authentication bypass in phpBB has been disclosed, allowing an attacker to log in as any user—including administrators—with a single HTTP request. The flaw affects phpBB versions 3.3.16 and 4.0.0-a2 (and earlier) and was discovered by Aikido on June 2, 2026; phpBB issued a fix on June 6 in version 3.3.17, while a 4.x fix is not yet available. Although remote code execution isn’t possible due to a separate admin password check, attackers could view private messages, create/modify/delete content and user accounts, impersonate staff, or deface forums. Admins should upgrade to 3.3.17 or migrate to master for 4.x; OAuth redirect handling may temporarily break. Full technical details will be published in a future report.
Showing 20 of 423 articles


