China-Nexus Actor Spy on US Researchers Undetected for a Year
China-linked hackers compromised US research institutions for a year using stolen RedCAP credentials. Google's team disrupted the campaign that exfiltrated sensitive research data.
ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know
The full HackWire archive — 3,892 stories, newest first.
China-linked hackers compromised US research institutions for a year using stolen RedCAP credentials. Google's team disrupted the campaign that exfiltrated sensitive research data.
SearchLeak exploits Microsoft 365 Copilot to steal emails, files, and MFA codes via trusted microsoft.com links. The one-click attack bypasses email security by exploiting user trust in Microsoft.
North Korean APT group Contagious Interview targets developers via phishing using recruitment and code review pretexts. They exploit trusted developer tools like GitHub to deliver supply chain malware, shifting from traditional endpoint attacks to developer-focused social engineering.
A critical OIDC flaw in SimpleHelp allows attackers to create privileged accounts without authentication, giving complete control over remote support used by IT providers and enterprises.
LiteLLM AI gateway has a critical vulnerability (CVSS 9.9) allowing low-privilege users to escalate to admin and execute code. Compromise exposes all AI provider keys and intercepted prompts.
FBI warns that crypto scam networks now hire cash couriers to extract victim funds directly, bypassing digital banking controls. This hybrid offline-online approach makes fraud harder to intercept than purely digital schemes.
ShinyHunters claims to have stolen 429,000 Council of Europe documents including payroll and employee data, threatening to leak them by June 16, 2026. The organization is investigating the alleged breach but declined to provide further details.
Cisco released emergency patches for CVE-2026-20262, a critical zero-day in Catalyst SD-WAN Manager enabling authenticated attackers root access. The file upload vulnerability allows unauthorized command execution on systems managing enterprise SD-WAN infrastructure. The flaw threatens thousands of
A supply-chain attack compromised Awesome Motive's CDN, delivering malicious code to 1.2M+ WordPress sites running OptinMonster, TrustPulse, and PushEngage. Hackers created rogue admin accounts and backdoor plugins for persistent access to affected installations.
Novo Nordisk disclosed a breach exposing clinical trial data and healthcare provider information. Though patient names weren't exposed, stolen biomarkers and health data could aid threat actors.
Ukrainian developer guilty of building malware for Conti, a ransomware gang that extorted $150M+ from 1,000+ organizations. His plea advances international prosecution efforts against cybercrime.
Chinese state-sponsored UNC6508 targets medical, military, and AI research across North America for intelligence. Active since 2023, it compromises clinical research and defense secrets.
The Gentlemen ransomware group shut down Mackay Sugar's operations on June 10, forcing two mills offline and disrupting Australia's sugar supply chain. Data theft status remains unclear as the company continues recovery efforts into mid-June.
Chrome zero-days are accelerating in 2026, but the real threat is forgotten code—abandoned packages and deprecated features still in production. Attackers exploit unmaintained software at scale across organizations, as shown by recent breaches in Oracle PeopleSoft and Arch Linux repositories.
NewCore raised $66M for unified identity management across humans, machines, and AI agents. It addresses a critical gap where traditional IAM wasn't built for AI systems and microservices.
ShinyHunters breached Infinite Campus, compromising 137,000+ school staff records including names, emails, and phone numbers. The extortion gang is demanding ransom and threatening to sell the stolen data on dark web marketplaces.
SearchLeak, a critical flaw in Microsoft 365 Copilot Enterprise, allows attackers to steal emails, documents, and files via a malicious URL with just one click, bypassing authentication safeguards.
Chinese threat actors deployed InfiniteRed malware on vulnerable REDCap servers, stealing medical research data via authentication weaknesses and enabling persistence for lateral movement. The custom RAT affects North American research institutions and demonstrates critical risks in exposed research
Employees bypass security by building AI-powered automations and integrations outside official oversight, creating credential exposure, data risks, and compliance violations. CISOs are struggling to regain visibility and control over this "shadow development" sprawl.
US government suspended Anthropic's Fable 5 (released 72 hours prior) and restricted Mythos 5 over cyberattack risks. Threat actors were actively exploiting AI models to automate attacks and discover vulnerabilities.
Supply chain attack compromised 1.2M WordPress sites through three plugins. Malicious JavaScript injected hidden admin accounts and web shells, triggered only for logged-in admins to evade detection.
152 malicious Chrome extensions masked as wallpaper apps infected 105,000 users. They conduct data harvesting, adware distribution, and traffic fraud to inflate affiliate payments.
IT teams rush onboarding security by sharing temporary passwords via email and SMS, leaving credentials exposed to interception. This convenience-over-security approach results in weak passwords often remaining unchanged, giving attackers a simple path to initial network access.
AI-generated phishing now outpaces manual investigation. The article explains behavioral AI's role in email security, covers Device Code/OAuth threats, and recommends deploying anomaly detection tools and incident response playbooks.