
Canadian admits role in Snowflake data theft spree
A Canadian national has pleaded guilty to infiltrating Snowflake customer accounts and stealing data from at least 165 organisations as part of an extortion scheme.

A Canadian national has pleaded guilty to infiltrating Snowflake customer accounts and stealing data from at least 165 organisations as part of an extortion scheme.

Attackers exploited an Oracle database SQL injection flaw to embed a post-exploitation toolkit, compromising a corporate network. The khunt toolkit was installed directly within the database environment.

The Russian hacking group Laundry Bear is exploiting a previously patched Zimbra Collaboration vulnerability alongside phishing to compromise email servers, according to a CISA advisory.

An ongoing outage affecting Microsoft Teams, SharePoint, Excel, and the Microsoft 365 Admin Center began earlier today, with no resolution timeline provided.

Iran's Revolutionary Guard claims to have struck an Amazon Web Services data center in Bahrain with cruise missiles, marking a potential escalation in targeting commercial cloud infrastructure during Middle Eastern hostilities. AWS has not confirmed the attack or damage.

A security researcher found that India’s .bank.in registry, operated by IDRBT, exposed bcrypt password hashes, contact details, and login metadata of 5,576 bank employees via unauthenticated API endpoints for over a year. The flaw was fixed after disclosure in early June 2026.

ASIO Director General Mike Burgess disclosed that state-sponsored hackers had compromised an Australian critical infrastructure provider, acquiring credentials and mapping networks to cripple systems at a strategic moment. The agency is expanding dedicated teams and AI tools to counter evolving threats, including espionage linked to the AUKUS defense pact.

A nationwide outage in Deutsche Bahn's GSM-R wireless network forced the German rail operator to cancel all train services for over two hours, stranding passengers and exposing vulnerabilities in legacy critical infrastructure.

Xsolis, a U.S.-based healthtech company, disclosed a data breach affecting 1.39 million people after attackers gained network access through a targeted phishing attack on January 20, 2026. The exposed data includes names, addresses, Social Security numbers, and medical treatment details. The company has implemented additional security measures and is offering identity monitoring to affected individuals.

Thalha Jubair and Owen Flowers pleaded guilty to breaching Transport for London's systems in August-September 2024, disrupting refund services and exposing customer data. The attack forced password resets for 28,000 employees and incurred £29m in losses.

Nintendo of America confirmed a data breach involving internal employee survey data from TinyPulse, a third-party platform owned by WebMD Health Services. The incident, claimed by the Shadowbyt3$ extortion group, allegedly includes personal employee details, though Nintendo denies customer or financial data exposure.

The Icarus threat group exploited a compromised OAuth integration in Klue’s Battlecards app to steal Salesforce data from multiple organizations, prompting Salesforce to disable the integration while investigations continue. Cybersecurity firms ReliaQuest and Huntress confirmed their data was compromised in the attack.

ShapedPlugin's build system was breached in late May 2026, allowing attackers to push malicious updates for three premium plugins. The malware stole credentials, installed hidden backdoors, and exfiltrated WooCommerce order data from infected sites.

A cyberattack on Australia’s second-largest sugar producer, Mackay Sugar, has disrupted operations, leading to delayed harvests and potential financial losses for farmers. The company is gradually restoring systems but has advised growers to hold off on harvesting until full capacity is regained.

Symantec researchers discovered DragonForce ransomware using custom Go-based malware, Backdoor.Turn, to abuse Microsoft Teams TURN relays, masking C2 communications within trusted infrastructure during a December 2025 attack on a U.S. services company.

Hackers exploited a vulnerability in UpdraftPlus to access Awesome Motive’s CDN credentials, injecting malicious JavaScript into OptinMonster, TrustPulse, and PushEngage plugins. The attack created rogue admin accounts and installed persistent backdoors, requiring immediate remediation by site owners.

Google Threat Intelligence Group has attributed a stealthy, multi-year intrusion campaign against North American academic, medical, and military research institutions to a China-nexus actor called UNC6508, which deployed custom malware and abused cloud email compliance rules to exfiltrate data undetected for more than a year.

ShinyHunters stole data from Infinite Campus's Salesforce instance in March, leaking a 1.2 GB archive containing personal details for 137,100 school staff accounts. The K-12 platform serves over 3,200 districts and 11 million students.

Google Cloud customers across India continue to experience intermittent latency and packet loss after a fire at a third-party Delhi data center forced an emergency shutdown of networking equipment on June 9, isolating a local Point of Presence and degrading regional capacity.

Sygnia's 'Operation Highland' investigation reveals how Velvet Ant chained Nginx proxy modifications and a FastCGI execution bridge to reach an isolated network, then replaced PAM and OpenSSH binaries to harvest credentials and observe every administrative session.