Cyber Security News
Start. Stay. Grow.
Curated daily. The latest hacks, breaches, and cyber trends—humanized.
Daily cyber brief
Hacking Editorial Brief — June 17, 2026
China-Linked Actors Exploit Legacy REDCap Research Infrastructure
Chinese threat actors are conducting an active espionage campaign against U.S. and Canadian research institutions by exploiting legacy REDCap deployments. Attackers compromised REDCap upgrade processes to install persistent malware on systems used by academic, healthcare, and defense research networks. REDCap is widely deployed across research environments for data collection and survey management, making it a high-value target for intelligence gathering on ongoing research programs. The campaign demonstrates systematic exploitation of research infrastructure where security patching often lags due to operational constraints and limited IT resources in academic environments.
Rapid Exploitation of Fortinet FortiSandbox Vulnerabilities
Threat actors exploited three critical FortiSandbox vulnerabilities—CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089—within 24 hours of public disclosure. CVE-2026-39813 was patched just last week, indicating attackers maintained prepared exploit chains awaiting patch release to reverse-engineer vulnerabilities. The immediate weaponization timeline underscores the speed at which sophisticated actors are developing and deploying exploits for enterprise security infrastructure, particularly appliances positioned at network perimeters. FortiSandbox devices analyze suspicious files and URLs, making them strategic targets for threat actors seeking to bypass detection mechanisms.
FulcrumSec Escalates Novo Nordisk Extortion with Data Leaks
Cybercrime group FulcrumSec has begun releasing samples from what they claim is 1.3 terabytes of data stolen from pharmaceutical manufacturer Novo Nordisk, escalating a $25 million extortion demand. The breach represents a significant compromise of a major pharmaceutical company amid ongoing attacks on healthcare and pharmaceutical targets. Meanwhile, digital healthcare provider iRhythm disclosed a separate breach where attackers exfiltrated patient protected health information and proprietary data from third-party-hosted applications. Separately, malicious JetBrains Marketplace plugins deployed in a coordinated campaign since October 2025 have achieved nearly 70,000 installations, exfiltrating AI provider API keys from developer environments—a supply chain attack targeting the software development toolchain itself.
Sources: CSO Online · The Hacker News · GovInfoSecurity · Bleeping Computer
Around the Web
Last Updated: N/A

Hacks + Heists
Can computer hackers get inside your mind? | NCPR News
On today's show: a whodunit about hackers, 'Cyber Paleontologists', spy-vs-spy protocols, cryptic intelligence leaks, nuclear physics, high-precision ...
Read more →'Dangerous' AI Models Are Coming No Matter What | WIRED
The US government crackdown on Anthropic's Claude Fable 5 and Mythos 5 hides a glaring truth: AI models with advanced hacking capabilities will ...
Read more →China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
ESET researchers discovered two previously undocumented Windows variants of the SprySOCKS backdoor used by China-aligned FishMonger group, featuring k...
Read more →AUR Supply Chain Attack: 400+ Arch Packages Backdoored with Rootkit and Infostealer
An AUR supply chain attack compromised over 400 Arch Linux packages starting June 11, 2026, planting a Rust-based credential stealer and an eBPF rootk...
Read more →Palo Alto Networks PAN-OS GlobalProtect Authentication Bypass Under Active Exploitation
Palo Alto Networks warned that CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect portal and gateway, is being actively exp...
Read more →
Big Cyber
Trump's Anthropic crackdown rattles cyber defenders - Axios
AI researchers and cybersecurity leaders fear the U.S. government is setting a precedent that may discourage American AI companies from building ...
Read more →CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla ...
Read more →ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day
ShinyHunters successfully exploited a critical Oracle PeopleSoft zero-day vulnerability to compromise over 100 organizations across 300 vulnerable ins...
Read more →Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters
Google's Mandiant team confirmed that ShinyHunters actively exploited the Oracle PeopleSoft zero-day (CVE-2026-35273) between May 27 and June 9, 2026,...
Read more →
Hard Tech
React2Shell (CVE-2025-55182)
A 10.0 critical severity vulnerablility affecting server-side use of React.js, tracked as CVE-2025-55182 in React.js and CVE-2025-66478 specifically f...
Read more →Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer
We discovered three vulnerabilities that when chained together, allow for complete remote compromise:
Read more →Check Point - Wrong Check Point (CVE-2024-24919)
Gather round, gather round - it’s time for another blogpost tearing open an SSLVPN appliance and laying bare a recent in-the-wild exploited bug. This ...
Read more →Backdoor in XZ Utils allows RCE: everything you need to know - CVE-2024-3094
Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgentl...
Read more →Loading...
The Cybersecurity Chronicles
‘The Cybersecurity Chronicles: 2024‘ pulls back the curtain on the digital threats that shaped our world last year, revealing the human stories behind the headlines. From art galleries frozen by ransomware to prison tablets hacked with a minus sign, from British Library archivists racing to protect centuries of knowledge to Spotify users meticulously curating their digital identities – these stories illuminate how cybersecurity touches every aspect of modern life.
Author Mark Nole weaves together intimate portraits of the people on all sides of the digital battlefield: the defenders working through sleepless nights to protect critical infrastructure, the victims grappling with stolen identities and lost savings, and even the attackers themselves, operating from nondescript offices with project management software and performance metrics.
Through detailed reporting and narrative storytelling, Nole reveals how 2024 became the year when cybersecurity stopped being just a technical problem and emerged as a fundamentally human challenge. Whether you’re a security professional or simply someone trying to understand our increasingly digital world, these chronicles offer an unprecedented look at how technology shapes – and sometimes betrays – our trust, our privacy, and our lives.

Stay Updated with Cyber Security News
Get the latest cybersecurity headlines, breaking news, and expert insights delivered directly to your inbox. Stay ahead of threats and informed about the digital landscape.
Join thousands of cybersecurity professionals and enthusiasts. No spam, just valuable insights.