Icarus Extortion Group Steals Salesforce CRM Data
June 20, 2026 Market intelligence platform Klue disclosed a critical security incident on June 19, 2026. Threat actors compromised legacy integration credentials to steal OAuth tokens used to connect Klue with customer Salesforce environments.…
Mastra npm Supply Chain Attack: 144 Packages Compromised
June 17, 2026 On June 17, 2026, a software supply chain attack codenamed “easy-day-js” compromised 144 npm packages associated with the Mastra AI framework. Attackers hijacked a former contributor’s account to publish malicious versions…
UNC6508 Abuses Google Workspace Rules to Steal US Medical and Defense Research
June 16, 2026 Google’s Threat Intelligence Group has disrupted a China-nexus espionage campaign that hid inside North American medical and military research networks for more than a year. The threat actor, tracked as UNC6508, abused legitimate…
Cisco SD-WAN Zero-Day CVE-2026-20262: Active Root Exploit
June 15, 2026 Cisco has patched a critical zero-day vulnerability in its Catalyst SD-WAN Manager platform. The flaw, tracked as CVE-2026-20262, allows authenticated remote attackers to overwrite files and escalate to root privileges. CISA added the…
Novo Nordisk Clinical Trial Data Breach Exposes Patient and HCP Records
June 15, 2026 Danish pharmaceutical giant Novo Nordisk, the world’s largest insulin producer and maker of blockbuster GLP-1 drugs Wegovy and Ozempic, has disclosed a significant data breach. Attackers gained unauthorized access to internal IT…
Oracle PeopleSoft CVE-2026-35273: ShinyHunters Zero-Day RCE Under Active Exploit | June 2026
June 11, 2026 Oracle has issued an emergency security alert for CVE-2026-35273, a critical zero-day vulnerability in PeopleSoft Enterprise PeopleTools that enables unauthenticated remote code execution. The ShinyHunters extortion gang is actively…
Meta AI Support Breach Hijacks 20,000 Instagram Accounts
June 8, 2026 Meta has disclosed that attackers exploited a vulnerability in its AI-powered Instagram account recovery system to hijack more than 20,000 user accounts. Consequently, the breach raises serious questions about how AI-assisted support tools…
DentaQuest Data Breach Exposes 2.6M Accounts: ShinyHunters Leak
June 7, 2026 DentaQuest, one of the largest dental benefits administrators in the United States, confirmed a major data breach that exposed the personal and health information of approximately 2.6 million accounts. The incident was carried out by the…
Iranian State-Sponsored Hacking Group Handala Breaches Holocaust Victim Support Centre: 2M Documents Leaked
June 2, 2026 Iranian state-sponsored hacking group Handala breached the Holocaust Victim Support Centre in Israel on May 31, 2026. The group claimed responsibility for the attack and leaked over two million documents totaling more than one terabyte of…
Unpatched Gogs Zero-Day Enables Remote Code Execution on Git Servers
May 29, 2026 An unpatched zero-day vulnerability in the Gogs self-hosted Git service allows authenticated attackers to execute remote code on Internet-facing instances. The flaw, discovered by Rapid7 researcher Jonah Burgess, affects the latest release…