AUTO-UPDATED

Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attack

A massive data leak exposed 74,000 Fortinet firewall credentials, while critical vulnerabilities in Splunk Enterprise and SimpleHelp RMM are currently being exploited by attackers in the wild.

Key Points

  • A Russian-speaking group leaked credentials from 74,000 Fortinet firewalls and VPN gateways after accidentally exposing them on a server.
  • CISA added a critical, remotely exploitable vulnerability in Splunk Enterprise (CVE-2026-20253) to its Known Exploited Vulnerabilities catalog.
  • A critical flaw in the SimpleHelp RMM tool (CVE-2026-48558) allows unauthenticated attackers to gain full remote access to managed endpoints.
  • Attackers are actively exploiting three vulnerabilities in FortiSandbox, a platform essential for threat blocking and automated security responses.
  • Microsoft is developing a patch for a zero-day vulnerability in Defender (CVE-2026-50656) that enables local privilege escalation.

Why it Matters

These incidents highlight a significant escalation in supply chain and infrastructure risks, as attackers increasingly target the management tools that organizations rely on for security. The widespread exposure of administrative credentials and active exploitation of RMM software demonstrate that even robust security perimeters are vulnerable when foundational management platforms are compromised.
Help Net Security Published by Help Net Security
Read original