IT News Roundup: FortiBleed Firewalls, FFmpeg RCE, and Linux Kernel Root Exploit - June 29, 2026
A busy week in cybersecurity brings critical vulnerabilities across FFmpeg, Fortinet firewalls, the Linux kernel, and libssh2, alongside a major ransomware campaign targeting education.
The past week has been dominated by critical security vulnerabilities spanning multiple layers of the technology stack. From a remote code execution flaw in the widely-used FFmpeg media framework to a massive compromise of Fortinet firewalls affecting over 86,000 devices, IT teams face an urgent patching cycle. Meanwhile, the ShinyHunters ransomware gang has intensified its campaign against education institutions, and OpenAI launched new AI-powered security automation tools.
FFmpeg PixelSmash Vulnerability Enables Remote Code Execution
A critical vulnerability dubbed PixelSmash has been disclosed in FFmpeg, the open-source multimedia framework used by virtually every major media player, streaming service, and video processing pipeline. The flaw allows remote code execution (RCE) through specially crafted malicious video files.
Because FFmpeg is embedded in so many applications — from web browsers to enterprise content management systems — the attack surface is enormous. Any system that processes untrusted video input could potentially be exploited. Security researchers recommend updating FFmpeg immediately and validating all media uploads on servers that handle user-generated content.
Source: eSecurity Planet
FortiBleed 2026: Over 86,000 Fortinet Firewalls Compromised
A massive campaign targeting Fortinet FortiGate firewalls has resulted in the compromise of approximately 86,644 devices, according to researchers. The attack, dubbed FortiBleed 2026, exploited vulnerabilities that allowed attackers to extract credentials and gain unauthorized access to network perimeters worldwide.
To make matters worse, hackers have built a database of over 30,000 working Fortinet admin logins, which researchers warn is being actively traded on underground forums. Organizations running FortiGate appliances need to verify their devices against the compromised list and rotate all firewall credentials immediately.
Sources: Peterson Technology Partners, CyberNews
Linux Kernel "pedit COW" Root Exploit (CVE-2026-46331)
A privilege escalation vulnerability in the Linux kernel has been disclosed under CVE-2026-46331, nicknamed pedit COW. The flaw is an out-of-bounds write in the packet-editing action (act_pedit) within the traffic-control subsystem, which allows a local unprivileged user to gain root access on affected systems.
The vulnerability affects a core component of Linux networking that handles packet manipulation. Any system where untrusted users can interact with network namespaces or traffic controls is potentially at risk. Kernel patches have been released for major distributions, and administrators should apply updates as soon as possible.
Source: The Hacker News
Critical Flaw Discovered in Popular libssh2 SSH Library
A massive security flaw has been discovered in libssh2, one of the most widely deployed open-source SSH libraries. The vulnerability affects applications that rely on libssh2 for secure remote connections, including many automation tools, CI/CD pipelines, and infrastructure management platforms.
The exact nature of the vulnerability was disclosed on June 23, 2026, and affected versions need to be updated immediately. Organizations should audit their software dependencies for libssh2 usage and upgrade to patched versions without delay.
Source: CyberNews
ShinyHunters Ransomware Gang Targets Education Sector via PeopleSoft Exploit
The ShinyHunters ransomware group has launched a coordinated campaign targeting the education sector by exploiting vulnerabilities in Oracle PeopleSoft. The gang is running multiple parallel extortion tracks, threatening to leak sensitive data from universities and educational institutions.
Beyond education, ShinyHunters claimed several high-profile victims this month including Eastman Kodak, which confirmed unauthorized access after the group listed 2.2 million customer records on its leak site. The gang also released a 45 GB archive of data tied to Madison Square Garden Sports after the company reportedly declined to pay.
Sources: SWK Technologies, Peterson Technology Partners
OpenAI Launches Daybreak Security Platform with GPT-5.5-Cyber
OpenAI announced Daybreak, a new security platform built around the full version of GPT-5.5-Cyber. The initiative moves beyond vulnerability discovery into end-to-end patch automation, combining AI-powered analysis with automated remediation workflows.
The announcement also included Patch the Planet, an OpenAI initiative to support open-source maintainers by identifying and helping fix vulnerabilities in critical shared infrastructure. During safety evaluations, GPT-5.5 identified a Firefox vulnerability (CVE-2026-8390) that Mozilla patched two days before Pwn2Own Berlin.
Sources: OpenAI, Patch the Planet
Linux Foundation Launches Akrites Open-Source Security Framework
The Linux Foundation has launched Akrites, a new security framework designed to improve open-source software security through coordinated vulnerability response and disclosure. The initiative aims to bring more structure and accountability to how vulnerabilities in critical open-source projects are handled.
This comes as governments worldwide struggle with the open-source security crisis, with the U.S. expanding its Open-Source Software Security Initiative at CISA and promoting secure-by-design principles, memory-safe languages, and software bills of materials (SBOMs).
Sources: Help Net Security, CyberScoop
← Back to Blog