Cyber Security News
Start. Stay. Grow.
Curated daily. The latest hacks, breaches, and cyber trends—humanized.
Daily cyber brief
Hacking Editorial Brief – April 28, 2026
Chinese State-Backed Hacker Extradited Over COVID-19 Research Theft
Italy has extradited Chinese national Xu Zewei, 34, to the United States to face charges related to hacking U.S. universities and government entities to steal COVID-19 vaccine research during the pandemic. U.S. prosecutors allege Xu was involved in the HAFNIUM computer intrusion campaign, which compromised thousands of computers worldwide between 2020 and 2021. The case represents a significant law enforcement action against alleged state-sponsored cyber espionage targeting critical health research during a global crisis. HAFNIUM, a known advanced persistent threat group, has previously been attributed to Chinese state-backed operations focusing on intellectual property theft from research institutions.
Medical Device Giant Medtronic Discloses Breach; ShinyHunters Claims Responsibility
Medtronic has reported to federal authorities that cybercriminals breached its corporate IT systems, though the company states medical device operations were not affected. The prolific threat actor ShinyHunters has claimed responsibility for the attack, allegedly using phishing tactics to compromise the systems and steal over 9 million records containing personally identifiable information. Meanwhile, ShinyHunters is also linked to a separate breach at ADT, where the group reportedly obtained data on 5.5 million customers through phishing operations. Additionally, Israeli users have received threatening WhatsApp messages in what appears to be a psychological warfare campaign attributed to Iranian threat actor group Handala, following their established pattern of combining cyberattacks with intimidation tactics.
Sources: GovInfoSecurity · Al Jazeera · Nextgov · Mashable · JPost
Around the Web
Last Updated: N/A

Hacks + Heists
Medical Device Maker Medtronic Says It's Been Hacked - GovInfoSecurity
Medtronic has told federal authorities that cybercriminals hacked its corporate IT systems, but said the incident did not affect the medical ...
Read more →Axios npm Package Supply Chain Attack by State-Sponsored Actors
State-sponsored threat actors hijacked a core maintainer's npm account and published malicious versions of the Axios JavaScript library that delivered...
Read more →'I suspected I was being socially engineered.' Why crypto's hacking epidemic is getting even worse
The $1.5 billion Bybit hack in February 2025, a January $282 million theft from a single crypto holder, and, this month, the Drift Protocol attack are...
Read more →TH: Hacker steals personal data of 350,000 engineers - DataBreaches.Net
Prof Amorn Pimanmas, a director in the council's board, said that about a week ago a hacker breached the database containing members' personal data .....
Read more →Researcher Drops Two More Microsoft Defender Zero-Days, All Three Now Exploited in the Wild
Security researcher Chaotic Eclipse released RedSun and UnDefend proof-of-concept exploits for Microsoft Defender, with all three vulnerabilities now ...
Read more →
Big Cyber
Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack
Get the latest news, expert insights, exclusive resources, and strategies from industry leaders – all for free. Email. Cybersecurity Webinars.
Read more →Aflac Latest Victim in String of Cyberattacks Against Insurance Firms
Aflac has been identified as the latest target in a series of cyberattacks targeting insurance companies.
Read more →PBSD victim of $3.2 million cybersecurity incident - Pine Bluff Commercial
The Pine Bluff School District lost more than $3.2 million in a Dec. 17 cybersecurity incident that has since come under federal investigation, ...
Read more →Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202
The attacker cannot make changes to disclosed information (Integrity) or limit access to the resource (Availability)." Cybersecurity. On April 27, ...
Read more →
Hard Tech
React2Shell (CVE-2025-55182)
A 10.0 critical severity vulnerablility affecting server-side use of React.js, tracked as CVE-2025-55182 in React.js and CVE-2025-66478 specifically f...
Read more →Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer
We discovered three vulnerabilities that when chained together, allow for complete remote compromise:
Read more →Check Point - Wrong Check Point (CVE-2024-24919)
Gather round, gather round - it’s time for another blogpost tearing open an SSLVPN appliance and laying bare a recent in-the-wild exploited bug. This ...
Read more →Backdoor in XZ Utils allows RCE: everything you need to know - CVE-2024-3094
Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgentl...
Read more →Loading...
The Cybersecurity Chronicles
‘The Cybersecurity Chronicles: 2024‘ pulls back the curtain on the digital threats that shaped our world last year, revealing the human stories behind the headlines. From art galleries frozen by ransomware to prison tablets hacked with a minus sign, from British Library archivists racing to protect centuries of knowledge to Spotify users meticulously curating their digital identities – these stories illuminate how cybersecurity touches every aspect of modern life.
Author Mark Nole weaves together intimate portraits of the people on all sides of the digital battlefield: the defenders working through sleepless nights to protect critical infrastructure, the victims grappling with stolen identities and lost savings, and even the attackers themselves, operating from nondescript offices with project management software and performance metrics.
Through detailed reporting and narrative storytelling, Nole reveals how 2024 became the year when cybersecurity stopped being just a technical problem and emerged as a fundamentally human challenge. Whether you’re a security professional or simply someone trying to understand our increasingly digital world, these chronicles offer an unprecedented look at how technology shapes – and sometimes betrays – our trust, our privacy, and our lives.

Stay Updated with Cyber Security News
Get the latest cybersecurity headlines, breaking news, and expert insights delivered directly to your inbox. Stay ahead of threats and informed about the digital landscape.
Join thousands of cybersecurity professionals and enthusiasts. No spam, just valuable insights.