EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJUNE 20, 20263 min read

Security Briefing | June 20, 2026 - FortiBleed Update: Russian Attribution Confirmed, WordPress Plugin Exploited, Unpatchable Apple Exploit Surfaces

The FortiBleed campaign has now been attributed to Russian-speaking threat actors with 86,644 confirmed compromised FortiGate devices. Active exploitation of CVE-2026-4020 in the Gravity SMTP WordPress plugin is exposing API keys and OAuth tokens on roughly 100,000 sites. Meanwhile, researchers published an unpatchable hardware exploit, usbliter8, that breaks SecureROM on Apple A12 and A13 chips.

By EACA Summit Content Team

Security Briefing | June 20, 2026 - FortiBleed Update: Russian Attribution Confirmed, WordPress Plugin Exploited, Unpatchable Apple Exploit Surfaces

1. FortiBleed Update: Russian-Linked Actors Confirmed, 86,644 FortiGate Devices Compromised

New details have emerged on the ongoing FortiBleed campaign. The confirmed device count now stands at 86,644 compromised FortiGate appliances, and CISA along with security researchers now attribute the campaign to Russian-speaking threat actors. New analysis also reveals the root cause: a widespread failure by organizations to rename default accounts or rotate factory credentials, giving attackers a reliable target list before any brute force was needed.

Verified Facts

  • 86,644 confirmed compromised FortiGate devices as of June 19, 2026
  • Campaign attributed to Russian-speaking threat actors
  • Generic admin accounts and built-in Fortinet system accounts make up the majority of compromised credentials
  • CISA continues to urge Fortinet customers to secure devices immediately

Evidence

  • CISA advisory update
  • Fortinet security bulletin
  • SOCRadar credential analysis

Impact

Widespread compromise of network edge devices can lead to data exfiltration, lateral movement, and persistent access to critical infrastructure networks. Defenders must immediately audit and patch FortiGate appliances, rotate all credentials, and remove default accounts.

Confidence Level: High

The Hacker News | BleepingComputer

2. Gravity SMTP WordPress Plugin Under Active Exploitation (CVE-2026-4020)

Cracked cloud infrastructure leaking API keys, JWT secrets, and sensitive data while a hooded figure exploits a broken OAuth authentication chain, representing a credential exposure vulnerability.

Threat actors are actively exploiting CVE-2026-4020, an unauthenticated information disclosure vulnerability in the Gravity SMTP WordPress plugin installed on approximately 100,000 sites. The flaw allows extraction of API keys, secrets, and OAuth tokens. Both The Hacker News and BleepingComputer report active exploitation.

Verified Facts

  • CVE-2026-4020 is a medium-severity (CVSS 5.3) information disclosure flaw
  • Plugin installed on about 100,000 WordPress sites
  • Exploitation allows extraction of API keys, secrets, OAuth tokens
  • Active exploitation confirmed by multiple sources

Evidence

  • CVE-2026-4020
  • WordPress plugin advisory

Impact

Compromised API keys and OAuth tokens can lead to account takeovers, data breaches, and lateral movement in cloud environments. Organizations using Gravity SMTP should immediately update the plugin and rotate exposed credentials.

Confidence Level: High

The Hacker News | BleepingComputer

3. Unpatchable 'usbliter8' Exploit Breaks Apple A12/A13 SecureROM

Security researchers at Paradigm Shift published a working exploit, usbliter8, achieving arbitrary code execution in the SecureROM of Apple A12 and A13 chips. The vulnerability is burned into silicon and cannot be patched via software updates. The attack requires physical USB access and is not remotely exploitable.

Verified Facts

  • Exploit targets SecureROM in Apple A12 and A13 chips
  • Vulnerability is unpatchable as it is hardware-based
  • Requires physical USB access (not remote)
  • Published by Paradigm Shift researchers

Evidence

  • Paradigm Shift research publication
  • Apple security advisory (expected)

Impact While not remotely exploitable, the exploit poses a significant risk for forensic bypass, jailbreaking, and persistent compromise of devices in controlled environments. Defenders should enforce physical security controls for affected devices.

Confidence Level: High

The Hacker News | BleepingComputer

Also Noted

  • Law enforcement disrupted infrastructure associated with the SocGholish malware operation. No Ethiopia-specific cyber incidents were independently corroborated from the sources reviewed for this briefing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings