Skip to main content

Current cyber intelligence

Cybersecurity News: Latest Incidents & Threat Intelligence

Shadow Tier brings verified public reporting into one current view. Start with the latest incidents below, or compare the companies, sectors, attack patterns, impacts and countries connected to them.

216

Reports in 90 days

in the current rolling intelligence window

10

Active topics

represented in the same 90-day window

65

High priority

high or critical reports in 90 days

Latest reporting

Latest cybersecurity incidents

Showing 7390 of 216 reports published in the last 90 days.

Msg logoMisconfiguration or publishing error
Medium

Madison Square Garden Data Leak by ShinyHunters

The ShinyHunters group reportedly stole and leaked approximately 45 gigabytes of data from Madison Square Garden Entertainment and related entities. The leaked data is said to include corporate and customer information, as well as files referencing New York Knicks players and staff. The incident was reported on June 21, 2026.

Msg
Londonhydro logoRansomware
Medium

London Hydro Discloses Data Breach Affecting Customer Information

Canadian electricity provider London Hydro is investigating a data breach that potentially impacted the personal and account information of its customers. London Hydro is a local distribution company serving the City of London, Ontario. It serves roughly 170,000 residential, institutional, commercial, and industrial customers. On June 20, the electricity provider announced that hackers had broken into its systems and that customers’ data was likely accessed. “London Hydro and the appropriate authorities are currently investigating a data security incident which may have impacted a portion of personal information on some accounts,” the company said . The potentially affected data includes personal information such as names, addresses, email addresses, and phone numbers. Account information, including account and billing numbers, service addresses, pricing plans, contract dates, and meter numbers and types, might have been impacted as well. Advertisement. Scroll to continue reading. According to London Hydro, no financial or other sensitive information might have been compromised in the data breach.   “The incident did not involve access to financial information or other sensitive categories of information, such as your date of birth, government identification numbers, payment card details, or banking information,” the company said. London Hydro urges customers to be wary of suspicious activity related to their accounts and personal information, including phishing messages, emails, or phone calls. It’s unclear who is responsible for the attack. No known cybercrime group appears to have taken credit for hacking London Hydro. Related: North Korean Hackers Blamed for Mastra NPM Supply Chain Attack Related: More Cybersecurity Firms Disclose Impact From Klue Hack Related: What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks Related: Texas Parks & Wildlife Data Breach Affects 3 Million Individuals Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Jazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO.

Londonhydro
Comta logoRansomware
Medium

Como Furniture Enterprises Data Breach by LockBit

Como Furniture Enterprises, a mold design and manufacturing company based in Taiwan, was reported to have suffered a data breach discovered on June 19, 2026, with the LockBit ransomware group identified as the threat actor. The group has threatened to leak sensitive data unless their demands are met.

Comta
Riverfinancial logoRansomware
Medium

River Financial Corporation Ransomware Attack

[8-K] River Financial Corp Reports Material Event Ransomware hits River Financial (RVRF), disrupting some operations River Financial Corporation reported a cybersecurity incident involving ransomware affecting its network, including River Bank & Trust. An unauthorized threat actor accessed its environment on or about June 16, 2026, and ransomware was deployed across parts of its server infrastructure, discovered on or about June 19, 2026. The company quickly disabled affected administrative accounts and took impacted systems offline, and is working with a third-party forensic firm and external cybersecurity professionals to investigate and restore operations. The investigation into whether any personally identifiable information was accessed or taken is ongoing, and River has not yet determined whether the incident is reasonably likely to materially impact its business or financial condition. The company plans to amend this report within four business days after it determines additional information is available. Ransomware attack and operational disruption : An unauthorized threat actor deployed ransomware across parts of River’s server environment, impacting certain operations while the company investigates the scope, data exposure, and potential business or financial effects. Banking risk and cybersecurity analyst neutral River discloses a ransomware attack with unresolved business impact. River Financial Corporation describes a ransomware incident affecting portions of its server environment and some operations. The company has contained the attack by disabling affected administrative accounts and taking systems offline, and has engaged a third-party forensic firm and external cybersecurity professionals. The filing states that the full nature, scope, and impact of the incident are not yet known, including whether any personally identifiable information was accessed or exfiltrated. It also notes that River has not determined whether the event is reasonably likely to materially affect its business or financial condition. The company indicates it will amend this report within four business days after additional information is available. Future disclosures in company filings may clarify operational disruption, potential data exposure, and any financial consequences linked to remediation, potential liabilities, or longer-term cybersecurity investments. AI-generated analysis. How Rhea-AI works . Not financial advice. What cybersecurity incident did River Financial Corporation (RVRF) disclose? When did the River Financial (RVRF) ransomware attack occur and get detected? Has River Financial (RVRF) confirmed any data or personally identifiable information exposure? How has the ransomware incident affected River Financial’s (RVRF) operations? Has River Financial (RVRF) determined the financial impact of the cyber incident? What future disclosures has River Financial (RVRF) committed to regarding the cyberattack? Date of earliest event reported: June 19 , 2026 (Exact Name of Registrant as Specified in its Charter) (Former Name or Former Address, if Changed Since Last Report) (Address of Principal Executive Offices) (Registrant’s telephone number, including area code) Check the appropriate box below if the Form 8-K filing is intended to simultaneously satisfy the filing obligation of the registrant under any of the following provisions (see General Instructions A.2. below): Date of earliest event reported: June 19 , 2026 (Exact Name of Registrant as Specified in its Charter) (Former Name or Former Address, if Changed Since Last Report) (Address of Principal Executive Offices) (Registrant’s telephone number, including area code) Check the appropriate box below if the Form 8-K filing is intended to simultaneously satisfy the filing obligation of the registrant under any of the following provisions (see General Instructions A.2. below): ☐ Written communications pursuant to Rule 425 under the Securities Act (17 CFR 230.425) ☐ Soliciting material pursuant to Rule 14a-12 under the Exchange Act (17 CFR 240.14a-12) ☐ Pre-commencement communications pursuant to Rule 14d-2(b) under the Exchange Act (17 CFR 240.14d-2(b)) ☐ Pre-commencement communications pursuant to Rule 13e-4(c) under the Exchange Act (17 CFR 240.13e-4(c)) Securities registered pursuant to Section 12(b) of the Act: None Name of each exchange on which registered Indicate by check mark whether the registrant is an emerging growth company as defined in Rule 405 of the Securities Act of 1933 (§ 230.405 of this chapter) or Rule 12b-2 of the Securities Exchange Act of 1934 (§ 240.12b-2 of this chapter). If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act.  ITEM 1.05 Material Cybersecurity Incidents. On or about June 16, 2026, an unauthorized threat actor gained access to the network environment of River Financial Corporation, including River Bank & Trust (together, “River”). River identified the activity on or about June 19, 2026, and determined that ransomware had been deployed across portions of its server environment. River promptly took containment measures, including disabling affected administrative accounts and taking impacted systems offline. River, with the assistance of a third-party forensic firm, is investigating the nature and scope of the incident, including whether any personally identifiable information was subject to unauthorized access or exfiltration. That investigation is ongoing. As of the date of this filing, the full nature, scope, and impact of the incident have not yet been determined. River has not yet determined whether the incident is reasonably likely to materially impact its business or financial condition. Certain operations have been impacted, but River is working with external cybersecurity professionals to fully restore these operations. River will file an amendment to this Current Report on Form 8-K within four business days after it determines that such information is available. ITEM 9.01 Financial Statements and Exhibits. Cover Page Interactive Data File (embedded within the Inline XBRL document) Pursuant to the requirements of the Securities Exchange Act of 1934, the registrant has duly caused this report to be signed on its behalf by the undersigned hereunto duly authorized.

Riverfinancial
Kmha logoRansomware
Medium

Kentucky Mountain Health Alliance Discloses Data Breach Affecting SSNs and Medical Records

Kentucky Mountain Health Breach Compromises SSNs and Medical Records Kentucky Mountain Health Alliance Inc. , a private nonprofit health center in Hazard, Kentucky, disclosed a data breach involving sensitive personal and medical information. A total number of 30,830 individuals were affected nationwide . The company disclosed the incident to the Massachusetts Office of Consumer Affairs and Business Regulation and to the New Hampshire Attorney General on June 19, 2026. Kentucky Mountain Health Alliance mailed notification letters to affected individuals. At this time. the details about the specific method of attack, the dates during which the incident took place or when it was discovered remains unknown. The types of information exposed included driver's licenses, medical records and Social Security numbers. Kentucky Mountain Health Alliance's response to the breach Kentucky Mountain Health Alliance has arranged for affected individuals to receive a free, two-year membership to identity monitoring services through Epiq's Privacy Solutions ID program. Affected individuals can enroll by visiting Privacy Solutions ID and entering the unique activation code included in their notification letter. Each letter contains a specific enrollment deadline. Individuals who need help with enrollment or have questions about the monitoring services can call Epiq directly at 866-675-2006, Monday through Friday from 9:00 a.m. to 5:30 p.m. EST. The company also directed affected individuals to the Federal Trade Commission at 1-877-438-4338 and the Massachusetts Office of Consumer Affairs and Business Regulation at 888-283-3757 for additional guidance on identity theft prevention. Kentucky Mountain Health Alliance can be reached at 606-487-9505 and is located at 279 East Main St., Hazard, KY 41701. SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION Affected information types not yet disclosed This browser does not support inline PDFs. Please download the PDF to view it: Download PDF Driver’s license or state identification card numbers Class actions settlements delivered to your inbox. SportsMed Physical Therapy Data Breach Exposes Health Information Trudeau Center Breach Affects 5,630 Individuals Alkegen Data Breach Exposes Personal and Protected Health Information Whitfield Hospital Breach Exposed Medical and Health Information Colorado Health Network; Kentucky Mountain Health Alliance Announce Data Breaches Data security incidents have been announced by the Colorado Health Network and Kentucky Mountain Health Alliance. In both cases, only limited information has been released about the nature of the incidents. Colorado Health Network Inc., a nonprofit organization that provides health and support services to individuals with HIV/AIDS across Colorado, has recently disclosed a data security incident. The breach notification does not state when the breach was detected or for how long the threat actors had access to its network, only that an unauthorized third-party accessed and removed files from its systems. The files have been reviewed and found to contain patient names in combination with one or more of the following: Social Security number, driver’s license/state identification card number, passport number, financial account information, debit/credit card information, health insurance information (which may include Medicaid/Medicare information), and medical information. The medical information may include, but is not limited to, diagnosis, diagnosis code, mental/physical condition, prescription information, and provider’s/location. Colorado Health Network started mailing notification letters to the affected individuals on June 18, 2026, and said it has received no reports to suggest that any of the exposed or copied information has been misused. The affected individuals have been advised to monitor their account statements, free credit reports, and explanation of benefits statements for suspicious activity, and to sign up for the complimentary credit monitoring and identity theft protection services that have been offered. Immediate Delivery of Checklist Link To Your Email Address This appears to have been a ransomware attack by the Cephalus ransomware group. Cephalus claimed on its dark web data leak site on August 28, 2025, that it was behind the attack and obtained more than 900 GB of data. The group’s data leak site is not currently accessible, so it is unclear whether the data was leaked online. The Texas attorney general was informed that 257 Texas residents were affected by the breach. Given that the primary location of business is Colorado, that would suggest that the incident affected more than 500 individuals and should have been reported to the HHS’ Office for Civil Rights (OCR) and added to the OCR data breach portal; however, it is not currently shown on the breach portal. Kentucky Mountain Health Alliance, a Hazard, KY-based nonprofit organization that provides primary and specialty care to the homeless, has disclosed a data breach that involved unauthorized access to patient data, some of which was copied in the incident. While data breach notices should be placed in a prominent location on the home page of the provider’s website under HIPAA, users are required to click on the “more” section and then select the notice from the drop-down menu. The notice states that the information compromised in the includes names plus one or more of the following: Social Security numbers, driver’s license numbers/state identification numbers, passport numbers, financial account information, debit/credit card information, health insurance information, and medical information such as diagnosis, diagnosis code, mental/physical condition, prescription information, provider’s name and location, and health insurance information. Notification letters were issued to the affected individuals on June 12, 2026. As with the data breach at Colorado Health Network (above), the breach notifications do not elaborate further on the nature of the incident, such as who potentially accessed the data (internal/external), when the incident was detected, or for how long the data was exposed. The website notice makes no mention of credit monitoring services; however, the notice issued to the Massachusetts Office of Consumer Affairs and Business Regulation states that 24 months of complimentary credit monitoring and identity theft protection services are being provided through Epiq. The number of affected individuals has yet to be publicly disclosed.

Kmha
Huntress logoRansomware
Medium

Huntress Affected by Klue Supply Chain Attack, Salesforce Data Exfiltrated

At least nine organizations have publicly acknowledged the impact of the supply chain attack on market intelligence platform Klue. The incident occurred on June 11-12 and affected Klue’s integration with Salesforce, resulting in data being exfiltrated from the Salesforce instances of multiple Klue customers, including several cybersecurity firms. On Friday, Klue confirmed previous security reports that the attackers used compromised legacy credentials to access its systems and compromise Salesforce integrations. “The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments,” Klue said. The company revoked the affected credentials and tokens, disabled the integrations across multiple services, and has been investigating the attack together with CrowdStrike and law enforcement. “Based on our investigation to date, the incident was limited to the affected third-party platforms, and there is no evidence that customer content stored within the Klue platform was impacted,” the company said. Advertisement. Scroll to continue reading. To date, at least nine Klue customers have disclosed impact from the incident, including cybersecurity firms HackerOne , Huntress , Jamf , OneTrust , Recorded Future , Snyk , and Tanium . Insurity and Sprout Social also notified their customers of the incident. All the affected companies pointed out that the intrusion was limited to the Salesforce instances and did not involve their systems, as Klue said in its incident notice. Across the board, the hackers stole business information from the affected organizations’ Salesforce CRMs, including sales account data and business contact information, such as names, email addresses, job titles, phone numbers, and business addresses. Salesforce disabled the Klue integration in the wake of the incident, and revenue intelligence platform Gong did the same on Friday, warning that the hackers exploited its Klue integration to access internal licensed user data. “We can confirm no direct impact on call recordings or customer transcripts. Examples of data accessed included user names, user business titles, and user emails,” Gong said. In its analysis of the incident, Huntress suggested that a threat actor named Icarus might have been responsible for the attack. Since then, Icarus has added Klue to its Tor-based leak site, claiming responsibility for the attack and threatening to publish the information stolen from Klue customers’ Salesforce instances. Per the threat actor’s posts, the data would be released on June 22, unless Klue and the affected organizations engage in negotiations. Related: Cybersecurity Firms Impacted by Klue Supply Chain Attack Related: Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages Related: ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems Related: Laravel-Lang Packages Poisoned for Malware Delivery Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity LastPass is the latest cybersecurity firm to have disclosed the impact from the Klue hack, which resulted in unauthorized access to customers’ Salesforce instances. A threat actor calling itself Icarus used a compromised legacy credential to access Klue’s systems and generate OAuth tokens to breach third-party platforms Klue integrates with, such as Salesforce. Icarus then accessed the connected Salesforce instances and exfiltrated data in bulk , using automated scripts. Salesforce and Gong have disabled the Klue integration in response to the attack, and over a dozen organizations have already confirmed the impact. Incident notifications from the affected companies reveal that the attackers accessed business data accessible through the Klue integration, and that no internal systems were compromised. LastPass’s notice follows the same lines: “The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data.” The company says it has discontinued access to Klue, rotated exposed tokens, notified law enforcement, and launched an investigation together with Klue and Salesforce. Advertisement. Scroll to continue reading. “It is important to note that the scope of this incident is limited to only those systems that integrate with Klue’s application. LastPass products, services, and infrastructure were not impacted in any way, and customer vaults remain secure. There is also no evidence the threat actor accessed any Gong-related data,” LastPass said. This week, in addition to LastPass, 8×8 and Pendo announced they were affected. Late last week, HackerOne, Huntress, Insurity, Jamf, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium disclosed the impact from the attack. BeyondTrust also said business contact and sales-related information was stolen from its Salesforce instance, but the notification went unnoticed. On its Tor-based leak site, Icarus has listed several organizations as having their Salesforce data stolen, including Swiss AI communications solutions provider Gms-net. SecurityWeek has emailed the technology company for a statement and will update this article if it responds. Icarus’s website is currently down but, before becoming inaccessible, it listed at least four other companies that have yet to publicly disclose being affected by the Klue incident, which brings the number of victims to roughly 15. Per Huntress’s estimates, however, numerous other Klue customers were likely impacted by the data breach and are expected to come forward. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication

Huntress
Daikyonishikawa logoRansomware
Medium

DaikyoNishikawa Data Breach by LockBit

DaikyoNishikawa Corporation, a Japanese plastic products manufacturer, was reported to have suffered a data breach discovered on June 19, 2026, with the LockBit ransomware group identified as the threat actor. The group has threatened to release sensitive data unless their demands are met.

Daikyonishikawa
Legendsmn logoRansomware
Medium

Legendary Home Services Breached by NightSpire Ransomware

On June 19, 2026, US home services company Legendary Home Services (operating as legendsmn.com) was listed as a victim by the NightSpire ransomware group. The breach was publicly identified on ransomware-tracking platforms. Initial reports indicate a ransomware attack, but the exact number of affected individuals and specific categories of data compromised (such as names, addresses, phone numbers, email addresses, or payment information) remain unknown.

Legendsmn
Atcom logoRansomware
Medium

ATCOM Data Breach by Qilin Ransomware Group

ATCOM Outsourcing, a business services provider in Chile, was reported to have suffered a data breach discovered on June 19, 2026, with the Qilin ransomware group identified as the threat actor. The group threatened to release sensitive data unless negotiations were initiated.

Atcom
Kodak logoInfostealer
High

Kodak Confirms Data Breach After ShinyHunters Extortion Threat

24 billion stolen records exposed online. Here’s what to do A newly discovered database containing 24 billion stolen records is a reminder that personal information from data breaches, phishing campaigns, and infostealer infections continues to circulate online. The collection was exposed on the internet before being taken offline. While researchers can’t confirm exactly whose information was included, the discovery is a good opportunity to check whether your email addresses, passwords, or other personal data have already been exposed. Researchers at Cybernews found a publicly exposed database holding more than 8.3 TB of data. The data, consisting of 24 billion credential records, reportedly came from 36 sources, including numerous Telegram channels, prior breach compilations, collections of infostealer logs, and some datasets apparently exported directly from live servers. Because the data came from different sources there are some differences in what the records contain and how they are organized. Some records were structured infostealer logs containing usernames, email addresses, and plaintext passwords, and the associated login URL. Infostealers are a type of malware designed to steal sensitive information from infected devices, such as your home computer. An infostealer log from a single infected device can include passwords stored across all browsers, active session cookies and tokens (including those that bypass multi-factor authentication), autofill data, device fingerprints, and sometimes crypto wallets or messaging accounts. The complete bundle is what ends up in logs such as those seen by the Cybernews researchers. Roughly 1.7 billion of the records came from hacking-related Telegram channels, mainly English and Russian, including at least one that was focused on stolen credit card data. The exposed database was hosted on an Elasticsearch cluster. Elasticsearch is a tool used to quickly store and search lots of data. If an Elasticsearch server lacks passwords,  authentication , or network restrictions, it can be accessed by anyone who finds it online. Without protections such as passwords or a firewall, anyone can read, copy, change, or even delete its data. Other documents in the dataset contained information about known vulnerabilities, articles about breaches, and social media posts about cyberattacks. This suggests the owner actively monitors security news and vulnerabilities and enriches the credential hoard with fresh breach information, either for a commercial “monitoring” service or for offensive use. A few years ago, we wrote about what was called the “mother of all breaches,” where the source of the dataset was later identified as data breach search engine Leak-Lookup. This newly discovered 24 billion record exposure is in the same league as that previous mega‑dump, but appears more heavily weighted toward fresh infostealer logs, rather than older, static breach data. Since the data was taken out of public view soon after the discovery, the researchers were unable to fully retrace everything they had found or determine how many duplicate records it contained. That’s reassuring because it reduces the chances of cybercriminals finding the database, but reused passwords may still put accounts at risk. And we still don’t know the purpose for the data collection in the first place. It’s good to be aware of how much information about you is out there and who’s gathering it, but it’s even more important to know exactly which information they have, since that is what they can use against you. 1. Check if your data has been exposed online using our Digital Footprint Portal . 2. If you discover exposed passwords, change them immediately and make sure you aren’t reusing the same password across multiple accounts. Prioritize updating your important accounts such as email, banking, shopping, and social media accounts. 3. Turn on multi-factor authentication (MFA) wherever possible, since it can help protect accounts even if a password has been exposed. Infostealers often spread through malicious ads, fake browser updates, and one-click downloads. Avoid clicking sponsored ads, and instead visit official websites directly. Download software only from trusted sources such as official vendor sites or app stores. Another increasingly popular technique is  ClickFix , a social engineering attack that tricks users into infecting their own devices. Never run commands or scripts copied from websites, emails, or messages unless you trust the source and understand what they do. Pirated software, game cheats, cracked tools, and shady browser extensions remain common sources of infostealer infections. Stick to reputable software and extensions, and be wary of anything asking for excessive permissions. Lastly, phishing emails are still a major threat. Be cautious of unexpected attachments, links, and urgent requests. If you’re unsure whether a message is legitimate, verify it through the company’s official website rather than the link in the message. You can also use Malwarebytes Scam Guard to check individual messages. Just upload a screenshot and we’ll let you know if it’s a scam. Breaches happen every day. Don’t be the last to know. President Gives China Gift Towards AI Leadership CISA Issues BOD on Patching Because, Apparently, Agencies Don’t Patch Is Your AI Infrastructure Ready for AI in Production? Claude Fable 5 – their most powerful model ever released to the public Are AI agents the new weakest link in the security chain? Our MSP has one userid that they share across their techs. Is this okay? Cyber Insurance Rates Down, but so is Coverage Is this the new norm thanks to AI? Microsoft releases over 200 patches this week Oracle Warns of Bug That Hackers Used to Breach Over 100 Companies OOPSIE. Japanese Energy Firm LOSES Drive with 10.9 Million Client’s Data Prez says he is considering “investing” in AI companies People becoming more thoughtful about AI UK tells big tech to block nudes – in 3 months Security News for the week ending June 12, 2026 – EU turns to Russian alternative to Microsoft Office, former twitter engineer who warned about Grok’s safety was fired and is now suing, Senate votes to not create new Pentagon branch, Cyber Force, feds shut down a couple of deep fake porn sites – call it groundbreaking and FISA section 702 lapses (lapsed) at Midnight (Friday).

Kodak
Tpwd logo
High

Texas Parks and Wildlife Department vendor data breach exposes over 3 million Texans' personal data

The Texas Parks and Wildlife Department (TPWD) publicly disclosed a data breach on June 18, 2026, affecting a third-party vendor responsible for selling Texas hunting and fishing licenses. The incident, detected by Texas Cyber Command, may have exposed the personal data of over 3 million license holders, including names, email addresses, residential addresses, phone numbers, driver's license information, and passport numbers.

Tpwd
Assuranceamerica logo
Medium

AssuranceAmerica Managing General Agency data breach exposes policyholder data

AssuranceAmerica Managing General Agency, LLC, an Atlanta-based nonstandard auto insurance provider, reported a data breach to the South Carolina Department of Consumer Affairs on June 18, 2026. The breach, detected on March 17, 2026, involved an unauthorized third party accessing and copying files from its computer systems after targeting a single employee. A review completed on June 15, 2026, identified that names, contact details, insurance policy information, driver/vehicle information, claims data, driver's license numbers, tax ID information, and potentially Social Security numbers were exposed.

Assuranceamerica
Hfmgt logo
High

Horizon Family Medical Group Data Breach

Reports emerged on June 18, 2026, of a possible data breach at Horizon Family Medical Group, a medical provider in New York's Hudson Valley region. Threat actor Incransom claimed to have stolen 7 TB of data, including medical information such as diagnoses, prescriptions, treatments, and lab results.

Hfmgt
Accenture logoUse of stolen credentials or exploit
Medium

FortiBleed Campaign Compromises Fortinet Devices, Exposing Accenture Credentials

Accenture was among the organizations affected by the 'FortiBleed' cyber espionage campaign, which compromised Fortinet firewalls and VPN gateways globally. The attackers gained unauthorized access by exploiting exposed Fortinet instances and brute-forcing credentials. The Canadian Centre for Cyber Security reported on June 17, 2026, about the widespread malicious activity.

Accenture
Mackaysugar logoRansomware
High

Mackay Sugar Ransomware Attack: The Gentlemen Group Claims Responsibility

Mackay Sugar, Australia's second-largest raw sugar producer, was actively recovering from a ransomware attack as of June 17, 2026. The incident, which became public on June 10, 2026, affected some of its operations, forcing two of its three mills in Queensland to shut down and halting cane harvesting. The Gentlemen ransomware group claimed responsibility on June 15, 2026, listing Mackay Sugar on its dark-web leak site and setting a countdown timer for the release of allegedly stolen data.

Mackaysugar
Samsung logo
Medium

FortiBleed Campaign Compromises Fortinet Devices, Exposing Samsung Credentials

The 'FortiBleed' cyber espionage campaign, which targeted Fortinet firewalls and VPN gateways globally, also impacted devices used by Samsung. Threat actors gained access by exploiting exposed Fortinet instances and used brute-force techniques to extract credentials. The Canadian Centre for Cyber Security issued an alert on June 17, 2026, regarding the widespread malicious activity.

Samsung
Onetrust logo
High

OneTrust Salesforce Environment Compromised via Klue Supply Chain Attack

OneTrust identified unauthorized activity in its Salesforce environment on June 17, 2026, linking it to the broader Klue third-party integration incident. The exposure appears limited to CRM-related data accessible through the Klue-Salesforce integration. OneTrust took containment measures and began notifying affected customers.

Onetrust

Explore the intelligence

Explore current intelligence taxonomies

Explore the intelligence

Questions about current cybersecurity intelligence

Explore concise answers about the latest reporting, intelligence taxonomies and the rolling coverage metrics on this page.

12 answers across 4 topics

How to read and use the current intelligence overview.

What does this cybersecurity intelligence overview contain?

It brings source-backed cybersecurity reports from the rolling 90-day window into one view, then connects them to companies, sectors, attack patterns, impacts and affected countries.

Where should I start exploring?

Start with Latest reporting for individual incidents, or use the taxonomy section to compare recurring patterns across industries, consequences and locations.

Does this page list every cybersecurity incident?

No. It is a curated view of public reports that meet Shadow Tier's publication and classification criteria, not an exhaustive record of every incident worldwide.

Browse current topics