Cyber Security News

Start. Stay. Grow.

Curated daily. The latest hacks, breaches, and cyber trends—humanized.

Daily cyber brief

Hacking Editorial Brief — June 13, 2026

ShinyHunters Exploits Oracle PeopleSoft Zero-Day in University Breaches

The ShinyHunters extortion group leveraged CVE-2026-35273, an unpatched zero-day vulnerability in Oracle PeopleSoft, to breach enterprise systems and exfiltrate sensitive data from multiple universities. The campaign represents a tactical evolution for the group, which has historically relied on purchased access or social engineering rather than zero-day exploitation. The vulnerability allowed unauthorized access to PeopleSoft installations before Oracle issued remediation guidance. Organizations running PeopleSoft should immediately review Oracle's security advisories and implement available mitigations while monitoring for indicators of compromise related to this attack vector.

Supply Chain Attack Compromises 400+ Arch Linux AUR Packages

Attackers hijacked over 400 packages in the Arch User Repository, modifying build scripts to deploy an information stealer and eBPF rootkit on systems that compiled the compromised packages. The campaign targeted the AUR's decentralized trust model, where community-maintained packages lack the centralized security review applied to official repositories. The attack demonstrates continued threat actor focus on open-source supply chains as high-value targets for persistent access and credential theft. In related activity, Russia-linked COLDRIVER has accelerated malware development since May 2025 with multiple new variants, indicating increased operational tempo. Meanwhile, Meta disclosed that attackers exploited its AI-powered support system to hijack over 20,000 Instagram accounts through automated password reset abuse, highlighting emerging attack surfaces created by AI-driven customer service tools.


Sources: The Hacker News · WIU Cybersecurity Center · The Hacker News · BleepingComputer

Around the Web

Last Updated: N/A

Hacker icon

Hacks + Heists

Ozempic Drug Maker Loses Clinical Trial Data in Hack - GovInfoSecurity

A hack on Danish pharmaceutical manufacturer Novo Nordisk has compromised some patients' clinical trial information, the maker of popular weight ...

Read more →

Iranian hacker group alleges it breached Bakersfield, Visalia, Chico water systems

An alleged breach of several California water systems by an Iranian-linked hacker group did not compromise any water production or delivery ...

Read more →

Cisco SD-WAN Zero-Day CVE-2026-20245 Actively Exploited in the Wild With No Patch Available

CVE-2026-20245 marks the seventh actively exploited zero-day in Cisco SD-WAN management software this year, with no security patch currently available...

Read more →

ShinyHunters Hackers Exploit Unpatched Oracle Bug to Steal Data From 100+ Companies

Hackers exploited an unpatched Oracle PeopleSoft flaw to breach over 100 organizations. No patch exists yet — here's what we know.

Read more →

Iran-Linked Group That Hacked Kash Patel's Email Threatens World Cup With Hijacked FBI Drones

The Iran-linked hacking group said it accessed footage from FBI-controlled drones and warned World Cup teams that they could be targeted.

Read more →
Cybersecurity icon

Big Cyber

The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm

... cybersecurity company said. "Additionally, LARVA-368 relies heavily on ... The individual's identity has since been outed by cybersecurity ...

Read more →

Beijing escalating AI espionage to catch up with the U.S. on tech, cybersecurity firm says - CNBC

U.S. cybersecurity giant CrowdStrike said China-based entities made over half of state-sponsored cyberattacks on tech firms for artificial ...

Read more →

UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign

Cybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of ...

Read more →

TD Bank holds customer responsible for $15K loss, won't say how account hacking ruled out

A cybersecurity expert says banks are increasingly blaming customers for fraud. When he appealed, the bank said the transactions were conducted using ...

Read more →
Technology icon

Hard Tech

React2Shell (CVE-2025-55182)

A 10.0 critical severity vulnerablility affecting server-side use of React.js, tracked as CVE-2025-55182 in React.js and CVE-2025-66478 specifically f...

Read more →

Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer

We discovered three vulnerabilities that when chained together, allow for complete remote compromise:

Read more →

Check Point - Wrong Check Point (CVE-2024-24919)

Gather round, gather round - it’s time for another blogpost tearing open an SSLVPN appliance and laying bare a recent in-the-wild exploited bug. This ...

Read more →

Backdoor in XZ Utils allows RCE: everything you need to know - CVE-2024-3094

Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgentl...

Read more →

Loading...

The Cybersecurity Chronicles

‘The Cybersecurity Chronicles: 2024‘ pulls back the curtain on the digital threats that shaped our world last year, revealing the human stories behind the headlines. From art galleries frozen by ransomware to prison tablets hacked with a minus sign, from British Library archivists racing to protect centuries of knowledge to Spotify users meticulously curating their digital identities – these stories illuminate how cybersecurity touches every aspect of modern life.

Author Mark Nole weaves together intimate portraits of the people on all sides of the digital battlefield: the defenders working through sleepless nights to protect critical infrastructure, the victims grappling with stolen identities and lost savings, and even the attackers themselves, operating from nondescript offices with project management software and performance metrics.

Through detailed reporting and narrative storytelling, Nole reveals how 2024 became the year when cybersecurity stopped being just a technical problem and emerged as a fundamentally human challenge. Whether you’re a security professional or simply someone trying to understand our increasingly digital world, these chronicles offer an unprecedented look at how technology shapes – and sometimes betrays – our trust, our privacy, and our lives.

Mark Nole Book Cover for Cybersecurity book

Stay Updated with Cyber Security News

Get the latest cybersecurity headlines, breaking news, and expert insights delivered directly to your inbox. Stay ahead of threats and informed about the digital landscape.

Join thousands of cybersecurity professionals and enthusiasts. No spam, just valuable insights.