Hugging Face AI Agent Breach
July 20, 2026 Hugging Face, the world’s largest open-source artificial intelligence platform, disclosed that attackers breached its production infrastructure using an autonomous AI agent system. The intrusion marks one of the first confirmed cases…
HelloNet APT Campaign Abuses ViPNet Update System
July 20, 2026 An advanced threat actor is abusing the update mechanism of ViPNet, a Russian-certified private networking suite, to implant persistent backdoors in government agencies and critical infrastructure across Russia. Dubbed HelloNet by Kaspersky…
Abbott Laboratories Double Cyber Incident: ShinyHunters Claims PII Records Stolen in Vishing Attack
July 19, 2026 Abbott Laboratories, one of the world’s largest medical technology companies, is investigating two separate cybersecurity incidents disclosed this week. One involves the ShinyHunters extortion gang, which claims to have stolen more than 30…
TrojPix Attack Exfiltrates Data From Air-Gapped Systems via Video Cables
July 6, 2026 Researchers at Shandong University have unveiled TrojPix, a novel attack that leaks data from air-gapped systems by modulating video cable electromagnetic emissions. The technique achieves a peak throughput of 8.1 Mbps and reaches distances…
Aflac Japan Data Breach Exposes 4.38 Million Customer Records
July 1, 2026 American insurance giant Aflac disclosed a major data breach after attackers compromised its Japan subsidiary and stole personal and bank account information of 4.38 million customers. The incident, discovered on June 25, 2026, represents…
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
June 24, 2026 Cybersecurity researchers at Novee Security have disclosed a critical new class of CI/CD workflow vulnerabilities called Cordyceps. This flaw allows unauthenticated attackers to hijack GitHub Actions workflows and seize full control of…
Icarus Extortion Group Steals Salesforce CRM Data
June 20, 2026 Market intelligence platform Klue disclosed a critical security incident on June 19, 2026. Threat actors compromised legacy integration credentials to steal OAuth tokens used to connect Klue with customer Salesforce environments.…
Mastra npm Supply Chain Attack: 144 Packages Compromised
June 17, 2026 On June 17, 2026, a software supply chain attack codenamed “easy-day-js” compromised 144 npm packages associated with the Mastra AI framework. Attackers hijacked a former contributor’s account to publish malicious versions…
UNC6508 Abuses Google Workspace Rules to Steal US Medical and Defense Research
June 16, 2026 Google’s Threat Intelligence Group has disrupted a China-nexus espionage campaign that hid inside North American medical and military research networks for more than a year. The threat actor, tracked as UNC6508, abused legitimate…
Novo Nordisk Clinical Trial Data Breach Exposes Patient and HCP Records
June 15, 2026 Danish pharmaceutical giant Novo Nordisk, the world’s largest insulin producer and maker of blockbuster GLP-1 drugs Wegovy and Ozempic, has disclosed a significant data breach. Attackers gained unauthorized access to internal IT…