Trust abuse, industrialised: one ERP zero-day, one poisoned integration, 74,000 firewalls
A synchronised disclosure cluster lands as one Oracle PeopleSoft zero-day claims victims across automotive, insurance and medical devices. A single compromised SaaS integration drains CRM data from security's best-known vendors. And verified admin credentials circulate for almost 74,000 FortiGate firewalls, with no new CVE at all.
Executive summary
- One ERP zero-day produced a synchronised disclosure wave. Automotive, agricultural-equipment and insurance names disclosed on a single day, all traced to the PeopleSoft flaw exploited weeks before its emergency patch; the campaign now spans 100+ organisations.
- A single SaaS integration drained CRM data from the security industry itself. Attackers compromised a market-intelligence app's infrastructure, harvested customer OAuth tokens and bulk-exported Salesforce data; at least 15 companies, many of them security vendors, confirmed exposure.
- No CVE required. The FortiBleed campaign circulated verified admin credentials for ~74,000 edge firewalls, harvested from exposed management interfaces and cracked configuration files, while regulators compressed exploited-flaw patch deadlines to as little as three days.
Key findings
PeopleSoft zero-day fallout: synchronised disclosures across automotive, agriculture and insurance
A global carmaker confirmed employee data theft across four countries, including banking and tax identifiers, with an equipment maker and an insurer's Japan arm disclosing the same day, all traced to the ERP flaw exploited as a zero-day from late May. The campaign's operators claim more than 100 victim organisations, roughly two-thirds in higher education.
New extortion group drains Salesforce estates through one compromised integration
Attackers pushed malicious code into a market-intelligence platform's integration infrastructure, harvesting customer OAuth tokens and bulk-exporting connected CRM data. At least 15 companies confirmed exposure, including some of the best-known names in security. The newcomer group behind it runs a leak site and extortion emails: supply-chain-native extortion with no encryption anywhere.
Six ISPs, one breach: up to 14.2 million email logins exposed
A telecoms giant disclosed that attackers compromised a shared email system serving six ISPs via a third-party software flaw, exposing addresses and passwords for up to 14.2 million accounts, including former customers, with only some passwords hashed.
FortiBleed: verified admin credentials for ~74,000 edge firewalls, no new CVE
A large-scale credential-compromise campaign exposed working administrator credentials for more than 73,900 internet-facing FortiGate devices across 194 countries, harvested via exposed management interfaces, stolen configuration files and hash cracking. Hardening guidance, brute-force follow-on activity and remediation ran throughout the fortnight.
Seven KEV additions and the three-day patch clock bites for the first time
CISA added a chainable Ubiquiti UniFi OS trio, a Lantronix command injection, PTC Windchill and Cisco Unified CM flaws, then a SharePoint deserialization RCE with a federal deadline of just three days, notable because the fix had been shipped in May without a bulletin entry, so bulletin-driven patching programmes missed it.
The broader pattern
- The connective tissue was always an over-trusted identity, token or credential sitting outside endpoint telemetry: an ERP service, an OAuth integration, a firewall admin login.
- Encryption-based ransomware was a footnote. Pure data-theft extortion dominated every major incident of the fortnight.
- The remediation clock is now regulatory. Three-day federal deadlines under BOD 26-04 are becoming the benchmark private programmes will be measured against, and three US state privacy regimes switched on in one day (1 July).
Sector lens
Suggested priorities to consider
Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.
Hunt PeopleSoft estates back to late May, then verify the emergency patch. Exploitation predated the advisory by two weeks; disclosure waves show victims are still surfacing a month later.
Audit third-party apps holding OAuth tokens into your CRM and SaaS. One compromised integration drained fifteen companies; scope tokens tightly and alert on bulk exports.
Get firewall management interfaces off the internet and rotate admin credentials. FortiBleed needed no CVE, only exposed management planes and reused credentials.
Reconcile your patching queue against KEV, not vendor bulletins alone. The SharePoint entry was patched in May but absent from the bulletin; bulletin-driven programmes missed it.
Check your US privacy-compliance posture against the 1 July state changes. New obligations, including neural-data protections and universal opt-out signals, took effect in one day.
These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.
Every incident this fortnight rode an identity or token that endpoint tools never see. Blacklight treats machine identities, OAuth grants and admin credentials as first-class telemetry: a service account exporting at ERP scale, a token pulling CRM data it never touched before, or a firewall admin logging in from new infrastructure is investigated autonomously, correlated against KEV the day entries land, with the full reasoning trail ready for your team.
Sources & methodology
Primary public sources this issue: Google Threat Intelligence Group / Mandiant campaign reporting · public disclosures (Nissan, Kubota North America, Aflac Japan, NAIC, Medtronic, KDDI) · CISA KEV alerts (23 and 25 June, 1 July 2026) and Binding Operational Directive 26-04 · Recorded Future and Fortinet PSIRT analysis of the FortiBleed campaign · Salesforce and Obsidian Security reporting on the integration-token campaign · BleepingComputer, SecurityWeek and The Hacker News incident reporting · US state privacy statutes effective 1 July 2026 · MITRE ATT&CK v15 for technique mapping. Attacker-claimed figures are labelled as claims.