Security Briefing | June 20, 2026 - FortiBleed Update: Russian Attribution Confirmed, WordPress Plugin Exploited, Unpatchable Apple Exploit Surfaces
The FortiBleed campaign has now been attributed to Russian-speaking threat actors with 86,644 confirmed compromised FortiGate devices. Active exploitation of CVE-2026-4020 in the Gravity SMTP WordPress plugin is exposing API keys and OAuth tokens on roughly 100,000 sites. Meanwhile, researchers published an unpatchable hardware exploit, usbliter8, that breaks SecureROM on Apple A12 and A13 chips.
By EACA Summit Content Team

1. FortiBleed Update: Russian-Linked Actors Confirmed, 86,644 FortiGate Devices Compromised
New details have emerged on the ongoing FortiBleed campaign. The confirmed device count now stands at 86,644 compromised FortiGate appliances, and CISA along with security researchers now attribute the campaign to Russian-speaking threat actors. New analysis also reveals the root cause: a widespread failure by organizations to rename default accounts or rotate factory credentials, giving attackers a reliable target list before any brute force was needed.
Verified Facts
- 86,644 confirmed compromised FortiGate devices as of June 19, 2026
- Campaign attributed to Russian-speaking threat actors
- Generic admin accounts and built-in Fortinet system accounts make up the majority of compromised credentials
- CISA continues to urge Fortinet customers to secure devices immediately
Evidence
- CISA advisory update
- Fortinet security bulletin
- SOCRadar credential analysis
Impact
Widespread compromise of network edge devices can lead to data exfiltration, lateral movement, and persistent access to critical infrastructure networks. Defenders must immediately audit and patch FortiGate appliances, rotate all credentials, and remove default accounts.
Confidence Level: High
The Hacker News | BleepingComputer
2. Gravity SMTP WordPress Plugin Under Active Exploitation (CVE-2026-4020)

Threat actors are actively exploiting CVE-2026-4020, an unauthenticated information disclosure vulnerability in the Gravity SMTP WordPress plugin installed on approximately 100,000 sites. The flaw allows extraction of API keys, secrets, and OAuth tokens. Both The Hacker News and BleepingComputer report active exploitation.
Verified Facts
- CVE-2026-4020 is a medium-severity (CVSS 5.3) information disclosure flaw
- Plugin installed on about 100,000 WordPress sites
- Exploitation allows extraction of API keys, secrets, OAuth tokens
- Active exploitation confirmed by multiple sources
Evidence
- CVE-2026-4020
- WordPress plugin advisory
Impact
Compromised API keys and OAuth tokens can lead to account takeovers, data breaches, and lateral movement in cloud environments. Organizations using Gravity SMTP should immediately update the plugin and rotate exposed credentials.
Confidence Level: High
The Hacker News | BleepingComputer
3. Unpatchable 'usbliter8' Exploit Breaks Apple A12/A13 SecureROM
Security researchers at Paradigm Shift published a working exploit, usbliter8, achieving arbitrary code execution in the SecureROM of Apple A12 and A13 chips. The vulnerability is burned into silicon and cannot be patched via software updates. The attack requires physical USB access and is not remotely exploitable.
Verified Facts
- Exploit targets SecureROM in Apple A12 and A13 chips
- Vulnerability is unpatchable as it is hardware-based
- Requires physical USB access (not remote)
- Published by Paradigm Shift researchers
Evidence
- Paradigm Shift research publication
- Apple security advisory (expected)
Impact While not remotely exploitable, the exploit poses a significant risk for forensic bypass, jailbreaking, and persistent compromise of devices in controlled environments. Defenders should enforce physical security controls for affected devices.
Confidence Level: High
The Hacker News | BleepingComputer
Also Noted
- Law enforcement disrupted infrastructure associated with the SocGholish malware operation. No Ethiopia-specific cyber incidents were independently corroborated from the sources reviewed for this briefing.



