NAIC says public data stolen in ShinyHunters' PeopleSoft breach

NAIC says public data stolen in ShinyHunters’ PeopleSoft breach Source: BleepingComputer The National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, and configuration files after breaching its systems by exploiting a zero-day vulnerability in an Oracle PeopleSoft server. […] Read original

June 29, 2026 Updated: October 8, 2026 1 min

LastPass confirms data breach in Klue supply chain attack

LastPass confirms data breach in Klue supply chain attack Source: BleepingComputer LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company’s OAuth tokens in the Klue supply chain attack earlier this month. […] Read original

Klue OAuth breach victim list grows as Icarus hackers claim attack

Klue OAuth breach victim list grows as Icarus hackers claim attack Source: BleepingComputer Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers’ Salesforce environments, as the new “Icarus” extortion group publicly claims the attack. […] Read original

June 19, 2026 Updated: October 8, 2026 1 min

Klue OAuth breach victim list grows as Icarus hackers claim attack

Klue OAuth breach victim list grows as Icarus hackers claim attack Source: BleepingComputer Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers’ Salesforce environments, as the new “Icarus” extortion group publicly claims the attack. […] Read original

June 19, 2026 Updated: October 8, 2026 1 min

Klue OAuth breach victim list grows as Icarus hackers claim attack

Klue OAuth breach victim list grows as Icarus hackers claim attack Source: BleepingComputer Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers’ Salesforce environments, as the new “Icarus” extortion group publicly claims the attack. […] Read original

June 19, 2026 Updated: October 8, 2026 1 min

Klue OAuth breach victim list grows as Icarus hackers claim attack

Klue OAuth breach victim list grows as Icarus hackers claim attack Source: BleepingComputer Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers’ Salesforce environments, as the new “Icarus” extortion group publicly claims the attack. […] Read original

June 19, 2026 Updated: October 8, 2026 1 min

Kodak confirms data breach claimed by ShinyHunters extortion gang

Kodak confirms data breach claimed by ShinyHunters extortion gang Source: BleepingComputer Kodak has confirmed that it’s working with external cybersecurity experts to investigate a security breach after hackers gained access to some of the company’s data. […] Read original

June 17, 2026 Updated: October 8, 2026 1 min

Kodak confirms data breach claimed by ShinyHunters extortion gang

Kodak confirms data breach claimed by ShinyHunters extortion gang Source: BleepingComputer Kodak has confirmed that it’s working with external cybersecurity experts to investigate a security breach after hackers gained access to some of the company’s data. […] Read original

June 17, 2026 Updated: October 8, 2026 1 min

Chinese hackers breach REDCap servers, steal medical research

Chinese hackers breach REDCap servers, steal medical research Source: BleepingComputer A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institution in North America. […] Read original

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities Source: The Hacker News The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest. Google’s Mandiant attributes it to the group it tracks as UNC6240, and dates the activity betw Read original