Geometric shards representing broken security from unpatchable exploits and RaaS attacks.

Daily Cybersecurity News - June 20, 2026

Unpatchable usbliter8 Exploit Breaks Apple Boot Chain

Apple A12 and A13 chips carry a permanent SecureROM flaw. Attackers with physical access can now run unsigned code on those devices.

The usbliter8 exploit targets a DMA underflow in the Synopsys DWC2 USB controller. On A12 and A13 it reaches SRAM because the IOMMU runs in bypass mode during early boot. It achieves code execution inside SecureROM in under two seconds via DFU over USB.

Public PoC covers iPhone XS through 11, SE 2, certain iPads, Apple Watch Series 4 and 5, and HomePod mini. A11 is unaffected. A14 and newer hardware blocks the path.

Researchers published full write-up and working code the day after coordinated disclosure with Apple.

AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution

One malicious web page can turn an AI browsing agent into a remote code execution vector on the host machine.

Attackers steer the agent to load their page. The page's JavaScript then reaches a privileged local service and spawns a shell. Microsoft researchers detailed the AutoJack exploit chain.

Affects Microsoft's AutoGen Studio specifically, and only its development builds with MCP support, the PyPI release was never exposed, and Microsoft fixed it the same day.

The chain needs no user interaction beyond the initial agent navigation.

CISA Warns Fortinet as FortiBleed Hits Devices

CISA is warning Fortinet users after attackers hit over 86,000 FortiGate devices in a campaign called FortiBleed.

Russian-speaking actors scanned for remote login endpoints and sprayed leaked credentials against them. Compromised accounts were mostly generic admin and default system logins.

Internet-facing FortiGate firewalls and VPN gateways are the main targets. Telecom, government and education sectors saw the heaviest hits across India, the US, Mexico, Colombia and Thailand.

The self-sustaining loop lets attackers monitor traffic on each device to harvest fresh credentials for the next round of compromises.

Klue OAuth Breach Victim List Grows As Icarus Hackers Claim Attack

Klue confirmed attackers stole OAuth tokens for customer Salesforce connections through a compromised legacy credential.

Icarus claimed the hit on their leak site and said they grabbed data from multiple partner Salesforce instances. Klue found the activity on June 12 and revoked the tokens right away.

The group is new and has only claimed two prior victims. Huntress and ReliaQuest traced the access to Klue's Battlecards integration and saw Python scripts pulling CRM records over the API.

Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity have all disclosed Salesforce data theft from the same incident.

Gentlemen RaaS Builds EDR Killer Suite

The Gentlemen ransomware as a service hands affiliates a growing toolkit for knocking out endpoint detection tools before encryption.

They maintain GentleKiller, a framework that targets hundreds of security processes across multiple vendors. Affiliates deploy it early to blind defenses on victim machines.

The angle is maturity: most RaaS crews reuse old scripts, while this group actively iterates on evasion code and distributes updates to partners.

Portfolio now covers over 400 distinct security processes with dedicated termination routines.