Related Threat Clusters
-
ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability
A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft has been exploited by the ShinyHunters group, leading to breaches of over 100 organizations, primarily in the education sector. The vulnerability…
65 articles · Updated June 11, 2026 -
LVMH Brands Fined 36 Billion Won for Salesforce Data Breaches
The Personal Information Protection Commission of South Korea has fined three luxury brands under LVMH, including Louis Vuitton and Dior, a total of 36.033 billion won (approximately $24.9 million) due to data breaches…
9 articles · Updated February 13, 2026 -
OrcaRouter AI Threat Report 2026 Highlights Rising Prompt Injection Risks
OrcaRouter Security Research released its AI Threat Report 2026, identifying prompt injection as the leading risk to large language model (LLM) applications, with a 340% increase in such attacks year-over-year. The…
3 articles · Updated June 22, 2026 -
Supply Chain Attack on node-ipc npm Package Exposes 822K Downloads to Credential Theft
A supply chain attack on the node-ipc npm package has compromised three versions (9.1.6, 9.2.3, 12.0.1) with credential-stealing malware. The attack exploited an expired domain to hijack a dormant maintainer account,…
11 articles · Updated May 15, 2026 -
New Pink Extortion Group Targets Microsoft 365 via Voice Phishing
The newly identified Pink extortion group has emerged, utilizing voice phishing (vishing) tactics to gain access to Microsoft 365 accounts. Researchers from Unit 42 have tracked the group under cluster designation…
9 articles · Updated June 4, 2026 -
Zero Trust Framework Expands Amid Rising AI-Driven Cyber Threats
Recent developments in cybersecurity emphasize the adoption of a Zero Trust approach across cloud services and enterprise networks, particularly in response to increasing AI-driven attacks. Organizations utilizing…
5 articles · Updated March 6, 2026 -
Malicious LLM Proxy Routers Compromise AI Security
A recent study identified 28 malicious LLM proxy routers that can modify AI service responses and access sensitive credentials. The research tested 28 paid routers and 400 free routers, revealing that nine injected…
2 articles · Updated April 15, 2026 -
University of Pennsylvania SSO Breach Exposes 1.2 Million Records
In 2025, the University of Pennsylvania suffered a significant data breach due to a compromised single sign-on (SSO) account. Attackers accessed the PennKey SSO, infiltrating internal systems including VPN, Salesforce,…
2 articles · Updated July 29, 2026 -
BlackFile Group Launches Vishing and Data Extortion Campaign Against Retail and Hospitality
Since February 2026, the BlackFile Group has targeted retail and hospitality sectors, employing vishing attacks to steal employee credentials. Palo Alto Networks' Unit 42 reported that the group uses spoofed VoIP…
2 articles · Updated April 27, 2026 -
EvilTokens Phishing Kit Exploits Microsoft 365 with AI-Driven BEC Tactics
In March 2026, the EvilTokens phishing kit emerged as a significant threat, allowing cybercriminals to bypass multi-factor authentication (MFA) and compromise Microsoft 365 accounts. This Phishing-as-a-Service (PhaaS)…
44 articles · Updated July 1, 2026
Recent Intelligence Reports
- McKesson Breach: ShinyHunters Claims 284m Patient Records — Cybernews · August 29, 2026
- McKesson discloses breach after ShinyHunters claims patient data theft — Bleepingcomputer · August 28, 2026
- McKesson discloses breach after ShinyHunters claims patient data theft — Bleepingcomputer · August 28, 2026
- Suspected TeamPCP hackers arrested over supply chain attacks — Cybernews · August 27, 2026
- Carhartt data breach exposes information of 12.9 million accounts — Bleepingcomputer · August 27, 2026
- Cybercriminals' Latest Medtech Target: Cook Medical — Mddionline · August 14, 2026
- Mystery attacker spent a year raiding Salesforce and ServiceNow portals — Theregister · August 13, 2026
- 153GB of stolen credentials surface after LiteLLM supply chain attack — Feeds2.Feedburner · August 13, 2026