Kodak confirms data breach claimed by ShinyHunters extortion gang
Kodak’s confirmation of unauthorized access to company data highlights the continuing shift from traditional ransomware toward data theft and extortion. In these attacks, cybercriminals may not need to encrypt systems o…
Jun 17, 2026
CISA warns of another cPanel plugin flaw exploited in attacks
The actively exploited LiteSpeed cPanel plugin vulnerability is a serious warning for hosting providers and organizations operating shared web-hosting infrastructure. Tracked as CVE-2026-54420, the flaw allows an attack…
Jun 17, 2026
144 Mastra npm Packages Compromised via Hijacked Contributor Account
I verified the incident details, including the hijacked contributor account, the 144 affected packages, the easy-day-js dependency, post-install execution, and the cross-platform information-stealing payload. ([The Hack…
Jun 17, 2026
Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
The active exploitation of three critical vulnerabilities in Fortinet FortiSandbox is particularly concerning because the affected product is itself designed to analyse suspicious files and detect advanced threats. Atta…
Jun 17, 2026
New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds
Rokarolla is a newly identified Android banking trojan that demonstrates how mobile malware is evolving from simple credential theft into full device takeover. The malware reportedly targets 217 banking and cryptocurren…
Jun 17, 2026
GhostTree Attack Abused Recursive Windows Junctions to Hide Malware
The GhostTree technique highlights an important weakness in security architectures that depend too heavily on recursive file scanning. Researchers demonstrated that attackers could abuse legitimate Windows NTFS junction…
Jun 17, 2026
Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting
The vulnerability discovered in Google Cloud’s Vertex AI Python SDK demonstrates how a seemingly minor weakness in cloud resource handling can undermine the isolation between separate customer environments. Researchers …
Jun 17, 2026
Malicious JetBrains Marketplace plugins steal AI API keys from developers
The discovery of malicious plugins on the JetBrains Marketplace demonstrates how attackers are increasingly targeting developers through the tools they use every day. At least 15 plugins, published through seven vendor …
Jun 17, 2026
ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
The reported ShinyHunters exploitation of Oracle PeopleSoft is a serious reminder that enterprise applications are now prime targets for extortion-driven attackers. PeopleSoft is not a small side application sitting qui…
Jun 12, 2026
Over 73,000 French govt employees affected in Tchap messenger breach
The Tchap breach is a strong reminder that even “secure” communication platforms can be exposed when attackers compromise user accounts. In this incident, France’s government messaging service Tchap, used by public-sect…
Jun 12, 2026
Pharma giant Novo Nordisk discloses breach of clinical trials data
The Novo Nordisk security breach highlights how cyberattacks on the healthcare and pharmaceutical sector are no longer limited to disrupting operations. They now directly target sensitive research, clinical trial data, …
Jun 12, 2026
Over 400 Arch Linux packages compromised to push rootkit, infostealer
The compromise of over 400 Arch Linux AUR packages is another reminder that the software supply chain has become one of the easiest ways for attackers to enter trusted environments. In this case, malicious packages were…
Jun 12, 2026