Maine Disables Data Breach Portal Due to Fake Submissions
Maine disabled its public data breach portal after attackers submitted fake reports on VRChat and Discord. The portal was a key resource for tracking 6,000+ breaches nationwide.
ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know
The full HackWire archive — 3,892 stories, newest first.
Maine disabled its public data breach portal after attackers submitted fake reports on VRChat and Discord. The portal was a key resource for tracking 6,000+ breaches nationwide.
Palo Alto Networks reports active exploitation of CVE-2026-0257, a critical GlobalProtect VPN authentication bypass enabling unauthorized portal access without credentials. Organizations must prioritize emergency patching.
Sniper Dz uses fake Facebook accounts impersonating government officials to scam MENA users with fraudulent offers of free mobile packages and financial compensation, escalating to phishing and credential theft.
FBI disrupted Outsider Enterprise, a China-based phishing-as-a-service ring that stole 3.8M credit card records and inflicted $1.9B in losses using AI-powered tools to impersonate trusted brands.
Former Iowa school IT employee Ezekiel Potter was sentenced to 21 months in prison for conducting a year-long cyberattack campaign using retained credentials. His attacks deleted accounts, disabled educational platforms, and caused tens of thousands in damages.
NPM 12 disables automatic script execution to prevent supply chain attacks exploited by malware like Shai-Hulud and TeamPCP. A major security overhaul for the JavaScript ecosystem.
Chinese state-backed hackers maintained undetected access to isolated critical infrastructure for 10 years through authentication system hijacking. Operation Highland bypassed air-gap protections and gave attackers complete visibility into administrative activity and credentials, exposing catastroph
Critical vulnerability CVE-2026-20253 in Splunk Enterprise allows unauthenticated remote code execution through unrestricted file manipulation, affecting thousands of enterprise deployments. With a CVSS score of 9.8, attackers can bypass authentication and execute arbitrary code with elevated privil
US government ordered Anthropic to disable Fable 5 and Mythos 5 on June 12, 2026, citing export control concerns. The directive barring "foreign nationals" access effectively took the models offline globally, halting the free rollout just three days after launch.
Anthropic took Fable 5 and Mythos 5 offline to comply with Trump export controls restricting foreign national access to frontier AI. Export controls now directly reshape industry operations.
U.S. orders Anthropic to suspend foreign access to Fable 5 and Mythos 5 citing unverified jailbreak vulnerabilities. Anthropic questions the severity and aims to restore access; other models remain available.
SRG replaces malware with social engineering to steal data from legal and financial firms, then extorts them. Their approach is simpler and more scalable than traditional ransomware.
ShinyHunters exploited a critical unauthenticated zero-day (CVE-2026-35273) in Oracle PeopleSoft's Environment Management Hub, breaching 300+ instances across 100+ organizations. The CVSS 9.8 flaw enables remote code execution without authentication, threatening sensitive payroll, HR, student, and f
Attackers compromised 400+ Arch Linux AUR packages by injecting a Rust credential stealer into abandoned package build scripts. The malware executes during compilation and can optionally deploy an eBPF rootkit for post-exploitation persistence.
Argentina's World Cup squad passports leaked due to failed redaction, exposing players to identity theft risks. The breach highlights persistent organizational failures in document security.
Velvet Ant maintained decade-long access by backdooring Linux authentication (PAM/OpenSSH). This granted persistent, undetectable master-key access across targeted networks.
Google sued a Chinese cybercrime group for weaponizing Gemini AI to auto-generate phishing messages at scale. The operation marks AI-powered social engineering becoming industrialized.
Over 400 Arch User Repository packages were hijacked in a supply chain attack injecting credential-stealing malware capable of achieving root-level access through modified build scripts. The compromise exposes critical vulnerabilities in community-driven package ecosystems.
Maine's breach notification portal was compromised by unauthorized users posting fake disclosures. The state disabled the system after discovering the fraudulent entries on its official website.
South Korea levied a record $400M fine against Coupang for breaching 30 million customers—a historic enforcement action. Allegations against IBM and AT&T for covering up foreign government hacks add further pressure. The week marks a clear regulatory shift: governments are moving from warnings to se
Over 400 AUR packages compromised to deliver rootkit and credential stealer. Attackers impersonated maintainers and hijacked packages, injecting malicious npm dependencies operating at kernel level.
A Ukrainian Conti conspirator pleaded guilty to ransomware attacks targeting 1,000+ organizations. Though the gang disbanded in 2022, members regrouped into successor operations with greater sophistication. The case underscores that dismantling individual syndicates fragments rather than eliminates
A decade-old phpBB authentication bypass lets attackers log in as any user via a single HTTP request, no password needed. The exploit works on default installations and affects thousands of forums worldwide.
Supply-chain attacks signal intent on dark web forums before public disclosure. Leaked credentials and source code appear generic but represent early warnings of widespread downstream compromise.