Isometric network nodes showing Klue OAuth breach and Fortinet VPN leaks.

Daily Cybersecurity News - June 18, 2026

Klue OAuth Breach Linked To Icarus Salesforce Thefts

Klue's OAuth token leak gave attackers a direct path into multiple companies' Salesforce instances.

Icarus used the stolen tokens to pull customer and sales records from several organizations over recent weeks. The group then started an extortion campaign demanding payment to keep the data private.

Klue spotted unusual outbound connections to a remote server around June 12 and alerted customers itself, before the extortion emails went out. The incident shows how a single third-party access point can open doors across unrelated environments.

Icarus is a new group (surfaced April 2026). The OAuth-token playbook mirrors the earlier Salesloft Drift and Gainsight thefts, but those were pinned on other actors, not Icarus.

FortiBleed Leak Exposes Fortinet VPN Credentials

A data leak called FortiBleed dumped Fortinet and FortiGate VPN credentials for over 73,000 firewall URLs across many organizations.

The collection lists login details for 73,932 devices worldwide. Researchers found the files on a public server and traced them to exposed management interfaces.

Many entries still use default or weak passwords. Attackers can reuse these credentials without needing a new exploit.

The dataset includes entries from organizations in over 100 countries.