SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data
Threat actor group SHADOWBYT3$ claims to have breached Nintendo, exfiltrating 859 MB of sensitive employee data via a third-party platform.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,782 stories synthesized.
Threat actor group SHADOWBYT3$ claims to have breached Nintendo, exfiltrating 859 MB of sensitive employee data via a third-party platform.
Microsoft's connectivity.office.com domain, used by IT pros to test Microsoft 365 network connectivity, is throwing untrusted certificate warnings after its SSL certificate expired on June 14, 2026.
A cyberattack on Russian software company Kaluga Astral disrupted tax reporting, cash registers, and digital certificate services for a week, affecting businesses and government agencies.
Check Point Research's weekly bulletin covers multiple incidents, including a ShinyHunters breach at the University of Nottingham, a Novo Nordisk data leak, and critical patches for LangGraph and Check Point VPN.
Threat actors Storm-2755 and Storm-2657 are using adversary-in-the-middle phishing to steal Microsoft 365 session tokens, then querying the Microsoft Graph API to identify HR staff and reroute employee direct deposits to attacker-controlled accounts.
Varonis researchers disclosed SearchLeak, a chain of three flaws in Microsoft 365 Copilot Enterprise that lets attackers steal emails, documents, and calendar data with a single click.
The ShinyHunters extortion gang stole personal data from over 137,000 school staff accounts by breaching the Salesforce instance of Infinite Campus, a student information system used by thousands of U.S. school districts.
A coordinated campaign of 23 malicious Chrome extensions has hijacked search queries from 758,000 users, routing traffic through affiliate brokers for monetization.
The Forum of Incident Response and Security Teams (FIRST) projects that 2026 will see nearly 66,000 CVEs, driven largely by autonomous AI agents that are automating the discovery of software flaws at unprecedented scale.
Two Chrome and Firefox extensions posing as ad blockers secretly exfiltrated full conversation histories from eight major AI platforms, affecting roughly 90,000 users.
A spear-phishing campaign abuses LNK files, PowerShell, and a Python loader to deploy the NarwhalRAT remote access trojan against Korean users.
The ShinyHunters extortion group claims to have breached the Council of Europe, stealing nearly 300 GB of data including payroll records for over 10,000 employees and threatening public release if ransom demands are not met.
Apple released iOS 26.6 beta 2 (build 23G5043d) to developers on June 15, 2026, continuing its pre-release testing cycle with anticipated security patches.
A supply chain attack against three popular WordPress marketing plugins served tampered JavaScript from vendor CDNs, enabling attackers to create hidden admin accounts and deploy a backdoor on over 1.2 million potentially exposed sites.
Microsoft's June 2026 Patch Tuesday update KB5094126 is causing severe regressions including system freezes, forced BitLocker recovery, and broken OneDrive integration.
A critical NDJSON injection flaw in Wazuh Manager (CVSS 10.0) allows unauthenticated attackers to delete alerts and tamper with SIEM data, with a patch available in version 5.0.0-beta3.
A new open-source security suite, SecSuite v0.1.0, unifies 21 OSINT, web, and API testing modules with local AI analysis, enabling fully offline penetration testing and interactive remediation.
Russian threat actors are exploiting CVE-2025-8088, a path traversal flaw in WinRAR, to deploy the GIFTEDCROOK information stealer against Ukrainian organizations.
A security researcher discovered an unlocked PHP installation page on a live malware distribution platform, enabling them to create an admin account and access the threat actor's dashboard.
SANS handler Didier Stevens introduces a new --stats option for his base64dump.py tool, enabling analysts to detect and reverse custom BASE64 encodings used in steganographic malware delivery, demonstrated on a malicious JPEG hiding a PE executable.
A phishing-as-a-service campaign dubbed 'Sniper Dz' is targeting users across the Middle East and North Africa via fake Facebook accounts and browser notification traps, Group-IB reports.
CI/CD Abuse Detector, an open-source tool using a large language model, flags suspicious changes to CI/CD pipelines to combat supply-chain attacks that exploit stolen developer credentials.
University researchers have developed HAMLOCK, a hardware backdoor that splits a malicious trigger between a neural network's weights and custom chip logic, evading all existing software-based detection tools.
Google's Threat Intelligence Group reveals Chinese-linked APT UNC6508 has been running a broad cyberespionage campaign since early 2025, targeting medical, military, and AI research organizations across North America.