The Security Drop- June Edition

Wednesday, July 1, 2026

Introduction

If June felt quiet on the surface, the June Security Drop tells a different story.

This edition covers Cisco patches being exploited weeks after their release, credential leaks exposing 74,000 Fortinet firewalls, and a ransomware group publishing 2.3 million ANC membership records after its demands went unmet.

Patches, leaks, and supply chain trouble dominate this round. Most of it comes back to two themes that never go away: things you have not patched yet, and credentials sitting somewhere they were never meant to be.

That Cisco Patch From Three Weeks Ago? Attackers Are Already Exploiting It

A high-severity vulnerability in Cisco Unified Communications Manager, tracked as CVE-2026-2030, is now being actively exploited in the wild, just three weeks after Cisco released a fix for it on June 3. The flaw lies in the WebDialer component of Cisco Unified CM and Cisco Unified CM Session Management Edition. It is a server-side request forgery (SSRF) vulnerability that allows an unauthenticated, remote attacker to write arbitrary files to the underlying operating system, ultimately escalating to root privileges—no login required.

Threat intelligence firm Defused caught the exploitation, flagging activity from a single IP address using file:// payloads to probe vulnerable devices. For now, the observed activity appears to be reconnaissance, with attackers scanning to identify vulnerable devices by attempting to write a test file. However, shortly after the exploitation was disclosed, the researchers who originally found the flaw published a full technical write-up and a proof-of-concept exploit.

The takeaway: If your organisation runs Cisco Unified Communications Manager or Unified CM SME and has not applied the June 3 patch yet, that needs to happen immediately. The gap between patch release and active exploitation was three weeks, and now that a working proof of concept is publicly available, that window is effectively closed. If you do not have a clear patch cadence for network infrastructure and communications systems, this is a good moment to build one.

A Single Phishing Email Just Exposed The Health Records Of 1.4 Million People

Xsolis, a U.S.-based healthtech company whose AI-powered software is used by more than 600 hospitals and health insurers, has confirmed that a targeted phishing attack on January 20 led to unauthorised access to its network and, with it, the personal and medical information of nearly 1.4 million individuals. The company detected the intrusion two days later, on January 22, and moved to contain it with the help of external cybersecurity experts. It is only now, five months later, that affected individuals are being notified, which is itself worth noting.

Xsolis has reset passwords across all user accounts, stepped up system monitoring, rolled out updated security measures, and accelerated employee security training. Affected individuals are being notified by mail and offered a 12-month identity monitoring and restoration service through Kroll.

The takeaway: For healthcare organisations and any company handling sensitive personal data, this is yet another reminder that your people are part of your security perimeter, and that phishing remains the most reliable way for attackers to get through the door. Anti-phishing training needs to be a continuous exercise, and it needs to be tested regularly with simulated phishing campaigns so staff can recognise the real thing.

Over 3 Million Texas Hunting And Fishing Licences Just Became A Privacy Problem

The Texas Parks and Wildlife Department (TPWD) has disclosed that a data breach at one of its external licence system vendors exposed the personal information of over 3 million individuals, specifically people who have purchased hunting and fishing licences in the state. The Texas Cyber Command discovered the intrusion and launched an investigation, but the agency has notably declined to name the third-party vendor responsible.

TPWD says there is no evidence that minors were involved or that any specific group was targeted. It is working with the vendor to implement new safeguards and enhanced monitoring. Affected individuals are being offered one year of free credit monitoring and advised to consider placing a credit freeze or fraud alert with the major credit bureaus.

The takeaway: For government agencies and public institutions that outsource any part of their citizen-facing services, the vendor security question is not optional. Every third party that touches citizen data should be subject to the same security standards and audit requirements as your internal systems.

74,000 Fortinet Firewalls Just Had Their Credentials Leaked

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning following a massive credential leak dubbed “FortiBleed,” in which usernames, email addresses and plaintext passwords for nearly 74,000 Fortinet firewall and VPN devices were found sitting on an exposed server.

The data was discovered by security researchers who confirmed the credentials were legitimate and that almost all the affected devices were still online. A Russian threat group is believed to be behind the operation, allegedly running approximately 1.16 billion credential attempts against over 320,000 FortiGate targets to build the dataset. The scale of who is in the leak is eye-opening. Among the organisations represented are Samsung, Mercedes-Benz, Foxconn, Chevron, Comcast and even Toyota. The affected devices span 21,632 unique domains and 194 countries, with the highest concentrations in India, the US, Taiwan, Mexico and the UAE.

The takeaway: For organisations affected by the leak, CISA’s guidance is clear: terminate all active SSL VPN and administrative sessions, and review your logs for signs of unauthorised access or lateral movement.

ShinyHunters Just Dumped 26 Million Madison Square Records, Days After The New York Knicks’ NBA Win

Just days after the New York Knicks ended their 53-year NBA championship drought, ShinyHunters published what it claims is a massive trove of stolen Madison Square Garden (MSG) entertainment data, after MSG declined to meet the group’s ransom demands before a June 15 deadline. The intrusion is said to have occurred on June 5, 2026.

The leaked dataset reportedly includes ticketing operations, customer account details and internal corporate documents tied to both the Knicks and the New York Rangers, over 26 million records and 42 gigabytes of files. Making matters worse, a class action lawsuit was filed the same day the data was released, alleging that attackers accessed sensitive visitor data through MSG’s surveillance and facial recognition systems.

The takeaway: For organisations that handle large volumes of customer and event data, this is a pointed reminder that your data footprint is bigger than you probably think. Ticketing systems alone hold names, contact details, payment history and attendance records for millions of people. That data needs to be protected with the same rigour as financial systems.

Hackers Poisoned The Mastra AI Framework, And 1.1 Million Weekly Downloads Made It A Very Big Deal

Microsoft’s threat intelligence team has confirmed that attackers compromised the Mastra AI framework, a popular npm ecosystem used to build AI agents, workflows and retrieval-augmented generation pipelines. The framework was compromised by poisoning over 140 packages after the attackers gained access to legitimate Mastra credentials. Mastra packages are downloaded roughly 1.1 million times per week, which gives you a sense of just how wide this kind of attack can be.

TeamPCP is the name being pointed to here. This is the same group behind attacks on the European Commission, GitHub, LiteLLM and TanStack, among others. Their tool of choice is a self-replicating npm worm called Shai-Hulud, and a more aggressive variant, Miasma, has now been spotted in recent campaigns. The good news is that the industry is finally moving towards structural fixes. GitHub, for instance, has announced that npm v12, due next month, will no longer allow dependency scripts to run by default.

The takeaway: Broadly, this is a sharp reminder that your software supply chain is an attack surface. Introduce lockfiles to pin exact dependency versions and prevent automatic resolution to newer, potentially poisoned packages. Consider implementing cooldown periods before pulling the latest package versions in production environments, and review which packages in your dependency tree have permission to install scripts.

A 2023 Ransomware Attack On A Children’s Dental Insurer Is Still Playing Out

MCNA Dental, one of the largest providers of government-sponsored dental benefits to children in the US and a subsidiary of UnitedHealth Group, has agreed to a proposed class-action settlement stemming from a 2023 LockBit ransomware attack that compromised the data of nearly 9 million patients, parents, and guardians. The attack happened in early 2023; LockBit demanded a $10 million ransom, MCNA declined to pay, and in April 2023, 700 gigabytes of data were posted publicly on LockBit’s dark web site. Three years later, the legal fallout is still being resolved.

Under the proposed settlement filed in federal court in Florida on June 12, MCNA will pay up to $2,500 per class member for documented out-of-pocket expenses, with the pool capped at $250,000 in total. All eligible class members will also receive two years of medical data monitoring services with $1 million in theft coverage, which, given the millions who potentially qualify, carries a stated retail value exceeding $3.2 billion. MCNA is also covering up to $2 million in settlement administration costs, $6.4 million in attorney fees, and $1.3 million in litigation costs, bringing the estimated settlement value to around $19 million.

The takeaway: For healthcare organisations and any entity handling government programme data, this case is a reminder that the cost of a breach extends far beyond the incident itself. Legal fees, settlements, regulatory fines and years of reputational damage will outlast any ransom demand.

Your Beats Earbuds Could Have Been Listening To You, And That Is Not Even The Biggest Apple News This Week

First, the earbuds. Apple has patched a high-severity vulnerability in the Beats Studio Buds, tracked as CVE-2025-20701, that could have allowed anyone within Bluetooth range to pair with the earbuds without the owner’s knowledge or consent and then listen through the microphone.

Researchers who originally found the vulnerability at a security conference in Germany last year described the potential impact in fairly stark terms: attackers within Bluetooth range could read and write the device’s RAM and flash memory, fully take over the headphones, and even hijack the trust relationship between the earbuds and a paired phone.

The takeaway: The patch is here now, but the gap between discovery in June 2025 and Apple’s fix in 2026 is worth noting. If you own the Beats Studio Buds, update the firmware now.

New Unpatchable Exploit Found In Apple’s A12 And A13 Chips

For the more unsettling part of this month’s Apple news, researchers at Paradigm Shift have disclosed a novel vulnerability in Apple’s A12 and A13 chips. These chips are found in iPhones from the XS through the iPhone 11 generation, and the vulnerability is in the device’s SecureROM, also known as BootROM. The critical detail here is that BootROM is immutable code embedded in the hardware itself, so it cannot be patched via a software update. The only mitigation for affected users is to move to newer hardware.

The takeaway: The practical risk for most people is low right now, since exploitation requires physical access to the device via USB. Even so, if you handle sensitive information on your phone and your organisation has a device refresh cycle, this is a reasonable prompt to prioritise upgrading.

Splunk Has A Critical Flaw That Lets Attackers In Without A Password

Splunk has patched a critical vulnerability, CVE-2026-20253, scoring a near-perfect 9.8 on the severity scale. It allows an unauthenticated attacker to create or truncate arbitrary files on affected systems and ultimately execute code remotely. The flaw exists in a PostgreSQL sidecar service endpoint that, remarkably, has no authentication controls at all. Splunk Enterprise versions below 10.2.4 and 10.0.7 are affected, while Splunk Cloud is not.

This matters beyond just Splunk users. Splunk is a security monitoring platform. Organisations use it to detect threats and investigate incidents. Compromising it not only gives attackers a foothold; it can also give them visibility into your entire security operation.

The takeaway: Versions 10.0.0 through 10.0.6 should be upgraded to 10.0.7, and versions 10.2.0 through 10.2.3 should be upgraded to 10.2.4. If patching is not immediately possible, consider network-level controls to restrict access to Splunk’s PostgreSQL sidecar endpoints while you work on the upgrade.

Four stories close to home this edition, three from Nigeria and one from South Africa. The thread running through all of them is the same one we keep coming back to: the people and credentials already inside your organisation are now the front line, not the firewall.

A Ransomware Crew Said It Had The ANC’s Data. Weeks Later, It Dumped 2.3 Million Records

On June 2, 2026, the ransomware group Black X claimed responsibility for a cyberattack on the African National Congress (ANC), South Africa’s governing party. It threatened to release sensitive data unless its demands were met. At first glance, it looked like the usual extortion playbook: make the claim, set a deadline, wait for a payment. The ANC did not pay.

Then the threat stopped being theoretical. On June 22, 2026, Black X published nearly 2GB of alleged ANC membership data on the deep web. Reporting put the haul at roughly 2.3 million records, and the exposed details reportedly reached all the way to the top of the party, including the personal information of President Cyril Ramaphosa, Deputy President Paul Mashatile, and national chairperson Gwede Mantashe. Beyond the political embarrassment, the dump immediately raised serious questions under South Africa’s Protection of Personal Information Act (POPIA), since a national membership register is exactly the kind of sensitive personal data the law is meant to safeguard.

The takeaway: For any membership-driven organisation, a political party, a union, a professional body, or a co-operative, the member register is one of your most valuable and most targeted assets. A threat to leak is not empty, and refusing to pay does not make the data safe. Decide your ransom and disclosure position before an incident, keep that register encrypted and access-controlled, and have a notification plan ready for regulators and members so you are not improvising under a published deadline.

INEC Says Nobody Hacked It. The Problem Was Someone Who Already Had The Keys

The controversy began on social media on May 30, 2026, when Lere Olayinka, a media aide to the Federal Capital Territory Minister, Nyesom Wike, posted screenshots showing the voter registration transfer details of Nollywood actor and Nigeria Democratic Congress aspirant, Emeka Ike. The screenshots appeared to come from INEC’s restricted Continuous Voter Registration (CVR) administrative platform rather than the public registration portal, and the post quickly snowballed into allegations that the entire voter database had been compromised.

In a statement signed by National Commissioner Mohammed Kudu Haruna on June 2, 2026, INEC was firm on one point: this was not an external hack. There was no breach of its ICT infrastructure, no external intrusion, and no compromise of the personal data of more than 90 million registered voters. Instead, the Commission’s audit trail pointed to insider access. Valid credentials issued to an authorised registration officer for the ongoing CVR exercise were used to retrieve a single voter record, which was then released without authority. INEC said it identified the user account, questioned the relevant personnel, and confirmed that the Department of State Services had opened a parallel investigation. Ike, for his part, threatened legal action over the exposure of his data.

The takeaway: An insider with legitimate access is harder to stop than an outside attacker because their access bypasses the firewalls and intrusion detection systems you have invested in. INEC’s audit trail worked, and that is the lesson worth copying: detailed logging tells you who did what after the fact. Pair it with least-privilege access, break-glass or dual-approval controls before anyone can pull sensitive production records, prompt revocation of access when an exercise ends, and a clear, enforced understanding that misusing credentials carries real consequences.

₦7.7 Billion In Airtime And Data, Generated From Stolen Staff Logins

The Nigeria Police Force National Cybercrime Centre (NPF-NCCC) has been working on a case that shows how far stolen credentials can go. It began after a leading telecommunications operator reported that staff login credentials had been compromised and used to access its billing infrastructure. Between October 1 and November 28, 2024, the suspects gained unlawful access to the company’s billing platform and fraudulently generated airtime, which was then converted into data bundles and sold through a nationwide network of vendors. The estimated loss was put at over ₦7.7 billion, and investigators say the scheme relied on a mix of insiders and external collaborators.

An initial wave of arrests, made public in January 2026, netted six suspects. A second phase carried out in May 2026 and announced on June 18, 2026, by NPF-NCCC liaison officer DSP Unwana Imah led to coordinated raids across Kano, Katsina and Zamfara states and the arrest of further suspects, including Musa Muhammed Kwandi, Nura Sadauki, Aminu Muhammed, and an IT specialist, Musa Hassan Mohammed. Through financial investigation and asset tracing, operatives recovered almost ₦90 million in cash, two residential houses in Kano, a mini-plaza, a Toyota RAV4, more than 400 laptops, around 1,000 mobile phones and several POS machines. The operator was able to reverse roughly 2,931.79 terabytes of fraudulently obtained data, valued at about ₦3.8 billion.

The takeaway: Compromised staff credentials remain the simplest way into core systems, and billing platforms are a direct line to revenue. Enforce multi-factor authentication on every privileged and billing-system account, monitor for anomalous airtime and data usage rather than waiting for month-end reconciliation to flag it, and review who can access revenue-generating infrastructure. Insiders were central to this scheme, so staff and vendor access reviews deserve as much attention as your perimeter.

Several Nigeria Breach Claims Are Circulating. Here Is Why “Unconfirmed” Matters

A cyber-intelligence alert dated June 12, 2026, flagged several incidents reportedly targeting Nigerian organisations. Before anyone panics, one detail deserves top billing: the alert was explicitly marked unconfirmed. The claims were attributed to threat actors and had not been independently verified, which is exactly how a responsible analyst should label them. That caution is not a mere formality, as 2026 has already produced a steady mix of genuine breaches and noisy, unsubstantiated ones.

For context that is verified: earlier in the year, a group known as ByteToBreach was tied to a wave of incidents touching Sterling Bank, the fintech payments backbone Remita, and the Corporate Affairs Commission, among others. Those reports prompted the Nigeria Data Protection Commission (NDPC) to open formal investigations and serve notices from April 1, 2026. The Corporate Affairs Commission temporarily closed its registration portal as a precaution. Alongside real incidents, dark web forums routinely carry listings claiming to sell Nigerian banking, telecom, and government data, and many of those claims are never substantiated.

The takeaway: Treat unverified threat-actor claims as leads to investigate, not facts to act on blindly, and do not dismiss them either. Use an alert like this to check your own logs, confirm whether the named data could plausibly be yours, and verify before notifying the public or considering any payment. A working relationship with credible threat-intelligence sources and the NDPC helps you quickly separate genuine exposure from background noise.

And that is the drop.

Patch what is yours, lock down who has the keys, and verify before you believe a leak claim. Forward this to one person on your security or GRC team who needs to read it.

Until the next drop, stay sharp.