Microsoft has attributed a supply chain attack on Mastra — an open-source TypeScript framework for building AI applications — to North Korean state actor Sapphire Sleet, also tracked as APT38 and BlueNoroff. The attribution, made June 19 with "high confidence," came after attackers compromised an npm maintainer account and poisoned over 140 packages with malicious code that ran straight from a postinstall hook.
The malware targeted cryptocurrency wallets from 166 browser extensions, including MetaMask and Coinbase Wallet, while also stealing browser history and system data. It ran on Windows, macOS and Linux, and switched off TLS certificate verification before phoning home.
Developers should check for easy-day-js dependencies. Mastra 1.13.0 and earlier and @mastra/core 1.42.0 and earlier are unaffected — anything newer needs checking.
Source: Infosecurity Magazine
Microsoft has attributed a supply chain attack on Mastra — an open-source TypeScript framework for building AI applications — to North Korean state actor Sapphire Sleet, also tracked as APT38 and BlueNoroff. The attribution, made June 19 with "high confidence," came after attackers compromised an npm maintainer account and poisoned over 140 packages with malicious code that ran straight from a postinstall hook.
The malware targeted cryptocurrency wallets from 166 browser extensions, including MetaMask and Coinbase Wallet, while also stealing browser history and system data. It ran on Windows, macOS and Linux, and switched off TLS certificate verification before phoning home.
Developers should check for easy-day-js dependencies. Mastra 1.13.0 and earlier and @mastra/core 1.42.0 and earlier are unaffected — anything newer needs checking.
Source: Infosecurity Magazine
The Education Authority (EA) wrote to parents at 23 schools in Northern Ireland on 25 June, warning that their children's personal data may have been accessed in the cyber attack first flagged to schools on 2 April. Sixteen of those schools had received no previous notification.
The attack targeted the C2K network, which handles IT for all schools across Northern Ireland, locking students out of accounts and resources during the lead-up to exam season. A 16-year-old boy was arrested and released on bail.
The EA says it still cannot confirm what personal data may have been affected, and that forensic analysis is a lengthy process. It has commissioned an independent review, notified the Information Commissioner's Office, forced a full password reset across the network, and is assisting the PSNI's criminal investigation. It reports no evidence of further breaches since the attack was detected, and says more notifications will follow as findings are confirmed.
Source: BBC News
The Education Authority (EA) wrote to parents at 23 schools in Northern Ireland on 25 June, warning that their children's personal data may have been accessed in the cyber attack first flagged to schools on 2 April. Sixteen of those schools had received no previous notification.
The attack targeted the C2K network, which handles IT for all schools across Northern Ireland, locking students out of accounts and resources during the lead-up to exam season. A 16-year-old boy was arrested and released on bail.
The EA says it still cannot confirm what personal data may have been affected, and that forensic analysis is a lengthy process. It has commissioned an independent review, notified the Information Commissioner's Office, forced a full password reset across the network, and is assisting the PSNI's criminal investigation. It reports no evidence of further breaches since the attack was detected, and says more notifications will follow as findings are confirmed.
Source: BBC News
Researchers at Unit 42 have uncovered a serious cloud attack technique called bucket hijacking, confirmed to work across Google Cloud, AWS and Microsoft Azure, all three of which were notified through responsible disclosure. The method exploits a simple but fundamental flaw: cloud storage bucket names are globally unique, meaning whoever owns the name owns the destination.
An attacker holding bucket deletion permissions inside the target environment can delete an active storage bucket, immediately re-register the same name — on Azure they'd need to be in the same tenant — and watch the original data stream of audit logs, telemetry and metrics flow silently into their environment. No alerts fire. No errors appear. The pipeline just keeps running.
Unit 42 has seen no sign of this being used in the wild, and notes that's cold comfort: once deployed, it would be extremely hard to detect. The biggest exposure is the broad storage-admin roles enterprises hand out routinely.
Unit 42 recommends restricting deletion permissions, enforcing data perimeter controls like AWS SCPs and Google Cloud VPC Service Controls, monitoring bucket deletion API calls closely, and enabling AWS account-regional S3 namespaces where available.
Source: Cybersecurity News
Researchers at Unit 42 have uncovered a serious cloud attack technique called bucket hijacking, confirmed to work across Google Cloud, AWS and Microsoft Azure, all three of which were notified through responsible disclosure. The method exploits a simple but fundamental flaw: cloud storage bucket names are globally unique, meaning whoever owns the name owns the destination.
An attacker holding bucket deletion permissions inside the target environment can delete an active storage bucket, immediately re-register the same name — on Azure they'd need to be in the same tenant — and watch the original data stream of audit logs, telemetry and metrics flow silently into their environment. No alerts fire. No errors appear. The pipeline just keeps running.
Unit 42 has seen no sign of this being used in the wild, and notes that's cold comfort: once deployed, it would be extremely hard to detect. The biggest exposure is the broad storage-admin roles enterprises hand out routinely.
Unit 42 recommends restricting deletion permissions, enforcing data perimeter controls like AWS SCPs and Google Cloud VPC Service Controls, monitoring bucket deletion API calls closely, and enabling AWS account-regional S3 namespaces where available.
Source: Cybersecurity News
A supply chain attack on market intelligence platform Klue, carried out June 11–12, has now been confirmed by roughly two dozen customers, including AlertMedia, Blackbaud, Deel, Tines, BeyondTrust and LastPass. Hackers used legacy credentials to steal OAuth tokens and bulk-exfiltrate Salesforce data. Klue has reportedly told customers the incident touches 195 of them in total.
Salesforce disabled the Klue integration on June 17 and has yet to re-enable it; Gong disabled it too.
The threat actor, Icarus, demanded ransom via a Tor leak site — but then got hacked themselves. Klue has reportedly told customers that Icarus was breached and the stolen data is now in another threat actor's hands. Klue says Icarus has begun deleting the data, and its leak site has gone dark, which suggests a ransom may have been paid. Klue hasn't confirmed either way.
Source: SecurityWeek
A supply chain attack on market intelligence platform Klue, carried out June 11–12, has now been confirmed by roughly two dozen customers, including AlertMedia, Blackbaud, Deel, Tines, BeyondTrust and LastPass. Hackers used legacy credentials to steal OAuth tokens and bulk-exfiltrate Salesforce data. Klue has reportedly told customers the incident touches 195 of them in total.
Salesforce disabled the Klue integration on June 17 and has yet to re-enable it; Gong disabled it too.
The threat actor, Icarus, demanded ransom via a Tor leak site — but then got hacked themselves. Klue has reportedly told customers that Icarus was breached and the stolen data is now in another threat actor's hands. Klue says Icarus has begun deleting the data, and its leak site has gone dark, which suggests a ransom may have been paid. Klue hasn't confirmed either way.
Source: SecurityWeek
Japan's Ground Self-Defense Force (JGSDF) unknowingly used malware-infected USB drives on classified military networks for almost a year, according to Nikkei's investigation of leaked internal documents. The counterfeit drives, manufactured in China, were distributed during earthquake relief operations in March 2024. The malware ran the instant a drive was plugged in, then sat quietly in the background.
By the time a soldier in Itami noticed his computer slowing down in February 2025, over 50 machines had connected to the infected drives — nearly half of them handling classified troop movement data. The malware matches a strain linked to a China-backed hacking group.
The JGSDF never disclosed the breach publicly, even as identical drives spread to Japanese factories and research institutions.
Source: Cybersecurity News
Japan's Ground Self-Defense Force (JGSDF) unknowingly used malware-infected USB drives on classified military networks for almost a year, according to Nikkei's investigation of leaked internal documents. The counterfeit drives, manufactured in China, were distributed during earthquake relief operations in March 2024. The malware ran the instant a drive was plugged in, then sat quietly in the background.
By the time a soldier in Itami noticed his computer slowing down in February 2025, over 50 machines had connected to the infected drives — nearly half of them handling classified troop movement data. The malware matches a strain linked to a China-backed hacking group.
The JGSDF never disclosed the breach publicly, even as identical drives spread to Japanese factories and research institutions.
Source: Cybersecurity News
Two young men convicted of the 2024 cyber-attack on Transport for London were repeat offenders well known to law enforcement long before the breach. Owen Flowers, 18, from Walsall, and Thalha Jubair, 20, from east London, pleaded guilty Monday to the attack, which disrupted TfL services for months, exposed data on millions of people and forced all 28,000 TfL staff to reset their passwords in person.
The trial heard both were part of Scattered Spider, the loose collective of young English-speaking cyber-criminals also linked to the Marks and Spencer and Co-op attacks.
Flowers first caught police attention shortly after turning 16, when officers issued a cease and desist order. Jubair has 22 previous convictions, started offending at 14, and had already received a youth rehabilitation order over Lapsus$-linked attacks on Nvidia and BT/EE. Both are wanted in the US, though the BBC understands American authorities won't pursue Flowers further; Jubair's US case involves alleged theft and extortion of $87m.
Sentencing is set for July 16. The National Crime Agency wants new Cyber Crime Risk Orders — proposed under Computer Misuse Act reforms — to let police restrict high-risk offenders before the next breach.
Source: BBC News
Two young men convicted of the 2024 cyber-attack on Transport for London were repeat offenders well known to law enforcement long before the breach. Owen Flowers, 18, from Walsall, and Thalha Jubair, 20, from east London, pleaded guilty Monday to the attack, which disrupted TfL services for months, exposed data on millions of people and forced all 28,000 TfL staff to reset their passwords in person.
The trial heard both were part of Scattered Spider, the loose collective of young English-speaking cyber-criminals also linked to the Marks and Spencer and Co-op attacks.
Flowers first caught police attention shortly after turning 16, when officers issued a cease and desist order. Jubair has 22 previous convictions, started offending at 14, and had already received a youth rehabilitation order over Lapsus$-linked attacks on Nvidia and BT/EE. Both are wanted in the US, though the BBC understands American authorities won't pursue Flowers further; Jubair's US case involves alleged theft and extortion of $87m.
Sentencing is set for July 16. The National Crime Agency wants new Cyber Crime Risk Orders — proposed under Computer Misuse Act reforms — to let police restrict high-risk offenders before the next breach.
Source: BBC News
Microsoft and law enforcement pulled off something new this week — dismantling two criminal hacking tools simultaneously instead of one at a time. Working under Europol's Operation Endgame alongside ESET, IBM X-Force, Proofpoint, BitSight, Lumen and police forces in Germany, the Netherlands and Denmark, they took down more than 200 command-and-control servers linked to Amadey and StealC. Europol puts the wider operation's haul at 326 servers.
The two tools are commonly used together: Amadey delivers malware, StealC steals passwords, crypto wallets and personal data. In just the first week of May, they infected over 140,000 computers globally. The operation also recovered roughly 27 million stolen credentials.
Microsoft says its Copilot AI helped lawyers connect both threats as a single criminal conspiracy under the RICO Act — a strategy it plans to expand.
Source: CyberScoop
Microsoft and law enforcement pulled off something new this week — dismantling two criminal hacking tools simultaneously instead of one at a time. Working under Europol's Operation Endgame alongside ESET, IBM X-Force, Proofpoint, BitSight, Lumen and police forces in Germany, the Netherlands and Denmark, they took down more than 200 command-and-control servers linked to Amadey and StealC. Europol puts the wider operation's haul at 326 servers.
The two tools are commonly used together: Amadey delivers malware, StealC steals passwords, crypto wallets and personal data. In just the first week of May, they infected over 140,000 computers globally. The operation also recovered roughly 27 million stolen credentials.
Microsoft says its Copilot AI helped lawyers connect both threats as a single criminal conspiracy under the RICO Act — a strategy it plans to expand.
Source: CyberScoop
A high-severity Android zero-day, CVE-2025-48595 (CVSS 8.4), is being actively exploited in targeted attacks — no user interaction required. Disclosed in Google's June 2026 Android Security Bulletin, the integer overflow in the Android Framework gives an attacker who already has code running on the device local privilege escalation, bypassing core security boundaries to reach sensitive system resources. Chained with other exploits, that becomes full device compromise.
Devices running Android 14, 15, 16 and 16 QPR2 are all affected. Patch level 2026-06-05 fixes the issue, and Google notified OEM partners over a month ahead of public disclosure. CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 2.
Update immediately. Sideloaders face the highest risk, since third-party app channels are exactly how the attacker's code gets on the device in the first place.
Source: Cybersecurity News
A high-severity Android zero-day, CVE-2025-48595 (CVSS 8.4), is being actively exploited in targeted attacks — no user interaction required. Disclosed in Google's June 2026 Android Security Bulletin, the integer overflow in the Android Framework gives an attacker who already has code running on the device local privilege escalation, bypassing core security boundaries to reach sensitive system resources. Chained with other exploits, that becomes full device compromise.
Devices running Android 14, 15, 16 and 16 QPR2 are all affected. Patch level 2026-06-05 fixes the issue, and Google notified OEM partners over a month ahead of public disclosure. CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 2.
Update immediately. Sideloaders face the highest risk, since third-party app channels are exactly how the attacker's code gets on the device in the first place.
Source: Cybersecurity News
A severe vulnerability chain in Splunk Enterprise is letting unauthenticated attackers execute remote code, no login required. Tracked as CVE-2026-20253 with a CVSS score of 9.8, the flaw targets the PostgreSQL Sidecar Service in Splunk Enterprise 10.0.0–10.0.6 and 10.2.0–10.2.3. Versions 9.4 and earlier, and Splunk Cloud Platform, are not affected.
The sidecar is active by default on AWS deployments, making those installations immediately exposed; on-premises deployments don't enable it by default. Researchers at watchTowr Labs found attackers can send crafted HTTP requests to internal API endpoints, manipulate file paths, inject malicious database connections, and ultimately overwrite Python scripts to run arbitrary commands. A non-weaponised proof of concept is already public.
Splunk has patched it in 10.0.7 and 10.2.4 — AWS users should prioritise updating immediately. If you can't patch yet, the sidecar can be disabled with [postgres] disabled = true in server.conf, but that breaks Edge Processor, OpAmp and SPL2 pipelines, so check what you're running first. Either way, Splunk Web on port 8000 shouldn't be reachable from the internet.
Updated 12 Aug 2026: Splunk updated its advisory on 18 June to warn of active exploitation in the wild, and CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day.
Source: Cybersecurity News
A severe vulnerability chain in Splunk Enterprise is letting unauthenticated attackers execute remote code, no login required. Tracked as CVE-2026-20253 with a CVSS score of 9.8, the flaw targets the PostgreSQL Sidecar Service in Splunk Enterprise 10.0.0–10.0.6 and 10.2.0–10.2.3. Versions 9.4 and earlier, and Splunk Cloud Platform, are not affected.
The sidecar is active by default on AWS deployments, making those installations immediately exposed; on-premises deployments don't enable it by default. Researchers at watchTowr Labs found attackers can send crafted HTTP requests to internal API endpoints, manipulate file paths, inject malicious database connections, and ultimately overwrite Python scripts to run arbitrary commands. A non-weaponised proof of concept is already public.
Splunk has patched it in 10.0.7 and 10.2.4 — AWS users should prioritise updating immediately. If you can't patch yet, the sidecar can be disabled with [postgres] disabled = true in server.conf, but that breaks Edge Processor, OpAmp and SPL2 pipelines, so check what you're running first. Either way, Splunk Web on port 8000 shouldn't be reachable from the internet.
Updated 12 Aug 2026: Splunk updated its advisory on 18 June to warn of active exploitation in the wild, and CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day.
Source: Cybersecurity News
A well-known hacking group has breached the University of Nottingham's systems, accessing "a significant amount of data" — including financial information — belonging to current students and alumni. The university confirmed the attack on 10 June and has since set up a helpline, notified police, and alerted the Information Commissioner's Office, the Office for Students and Action Fraud.
Students and graduates are rattled. Incoming law student Tolu Olufunwa, 17, said the news left her "scared" and wondering whether she had made the right decision, though she is still planning to start in September. Graduate Jacob Edwards, 23, criticised the university's communication as "so little and vague." Former applicant Margaret Ladipo, 19, has already changed her bank details and passwords after her national insurance number was caught up in the breach.
Source: BBC News
A well-known hacking group has breached the University of Nottingham's systems, accessing "a significant amount of data" — including financial information — belonging to current students and alumni. The university confirmed the attack on 10 June and has since set up a helpline, notified police, and alerted the Information Commissioner's Office, the Office for Students and Action Fraud.
Students and graduates are rattled. Incoming law student Tolu Olufunwa, 17, said the news left her "scared" and wondering whether she had made the right decision, though she is still planning to start in September. Graduate Jacob Edwards, 23, criticised the university's communication as "so little and vague." Former applicant Margaret Ladipo, 19, has already changed her bank details and passwords after her national insurance number was caught up in the breach.
Source: BBC News