ShinyHunters Disputes NAIC Data Breach Claims After Leak
A major insurance regulator just found itself at odds with the hacking group that broke into its systems. The NAIC data breach, first detected on June 11, has turned into a public dispute over exactly what was stolen and how serious the damage really is. The National Association of Insurance Commissioners, which oversees insurance regulation across all 50 states, confirmed

KDDI Data Breach Exposes Email Logins for 14 Million Customers
One of Japan's largest telecom providers has confirmed a serious security incident. A KDDI data breach has exposed the email credentials of up to 14.22 million customers — not just from KDDI itself, but from five additional internet service providers that shared the same compromised email infrastructure. The breach raises urgent questions about how shared systems across telecoms can turn

LastPass Confirms Data Breach in Supply Chain Attack
Password manager giant LastPass has confirmed a data breach affecting customer information stored in its Salesforce environment. The incident traces back to a supply chain attack on Klue, a third-party market intelligence platform, which gave hackers access to authentication tokens that connected into LastPass's CRM systems. Importantly, the breach did not touch user vaults or LastPass's core infrastructure. How the

WhatsApp Phishing Attack Spreads Via Fake Docs
A WhatsApp phishing attack is currently spreading across at least 11 countries, and it is more convincing than most. The messages arrive from people you know. The attachments look like invoices, financial reports, or account notices. And if you open one on a Windows PC, attackers can quietly take full control of your machine. Cybersecurity researchers have identified an active

Prinz Eugen Ransomware Targets Your Newest Files
A new ransomware strain called Prinz Eugen is drawing attention from security researchers, and its approach sets it apart from most threats in this space. Rather than encrypting files in a random or alphabetical order, Prinz Eugen targets the most recently modified files first. The goal is to lock down the data that matters most before defenders have a chance

ShapedPlugin Hit by Supply Chain Attack on WordPress Updates
A trusted update button just became a liability for thousands of WordPress site owners. ShapedPlugin, a vendor known for popular front-end and content display tools, confirmed that its official update system delivered backdoored software directly to paying customers. The company's free plugins alone power more than 400,000 active websites. Which gives a sense of how wide ShapedPlugin's reach extends across

FortiBleed Leak Hits Thousands of Fortinet VPN Devices
A new security incident known as FortiBleed has exposed Fortinet VPN credentials for tens of thousands of organizations worldwide. Researchers found a database containing login credentials for more than 73,000 Fortinet and FortiGate firewall devices. The data includes usernames, email addresses, and plaintext passwords. The list names household brands like Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, and Toyota. Security researcher

New Rokarolla Android Malware Hits 217 Banking Apps
A fake Chrome download could hand a stranger full control of your phone. So could a bogus TikTok app. Security researchers at Zimperium just uncovered a new Android banking trojan that does exactly that. The newly identified Rokarolla Android malware targets 217 banking and cryptocurrency apps, backed by 137 remote commands. This isn't a typical credential stealer. Rokarolla locks onto

Infinite Campus Data Breach Exposes 137K School Staff
A new wave of school cybersecurity trouble landed in March. Attackers broke into the Salesforce systems behind Infinite Campus, a student information platform used by school districts nationwide. The Infinite Campus data breach didn't touch student records directly. Instead, it exposed personal details for more than 137,000 school staff members across the country. The incident adds another entry to a

ServiceNow Data Breach Exposes Customer Records
ServiceNow has confirmed a security incident after a misconfigured API endpoint exposed enterprise customer data to unauthorized access. The ServiceNow data breach became public on June 9, 2026, when the company began notifying affected customers through a gated support bulletin and direct support cases. ServiceNow had already pushed a patch to hosted instances on June 5. But questions about how
