PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 16, 2026 Google’s Threat Intelligence Group (GTIG) uncovered a long-running Chinese cyber-espionage campaign targeting North American medical, academic, and military research institutions that remained undetected for over a year. GTIG has attributed the campaign with high confidence to UNC6508, a …

Infinite Campus Data Breach Exposes 137,000 Users Personal Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 16, 2026 Infinite Campus, a widely used student information system in U.S. K-12 schools, has disclosed a data breach affecting approximately 137,000 individuals. The incident has been linked to the ShinyHunters cybercriminal group, known for carrying out large-scale data …

OptinMonster Plugin Hack Exposes 1.2 Million WordPress Sites to Cyberattack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 16, 2026 A large-scale supply chain attack targeting widely used WordPress plugins has exposed more than 1.2 million websites to potential compromise after attackers injected malicious code into legitimate JavaScript files distributed through trusted CDN infrastructure. Security researchers at …

Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 16, 2026 The global ransomware landscape shifted noticeably in the first quarter of 2026, as former operators from well-known criminal groups began launching their own competing programs. Data leak sites tracked 2,122 new victims during Q1 2026, making it …

LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 16, 2026 A critical zero-day vulnerability in the LiteSpeed cPanel user-end plugin is being actively exploited in the wild, posing a serious threat to shared hosting environments worldwide. The flaw, tracked as CVE-2026-54420, enables privilege escalation to root level, …

Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 16, 2026 Cisco has disclosed a critical security issue in its Catalyst SD-WAN Manager (formerly vManage) that is now being actively exploited in zero-day attacks, raising concerns for enterprise network environments worldwide. The vulnerability, tracked as CVE-2026-20262, is an …

Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 16, 2026 Nearly 14,000 internet-facing SimpleHelp servers are exposed following the disclosure of a critical authentication bypass vulnerability tracked as CVE-2026-48558. The flaw raises serious concerns for enterprises using the remote monitoring and management (RMM) platform. Horizon3.ai identified the …

Microsoft Site Showing Warning Following Certificate Expiry

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 15, 2026 Microsoft seems to have failed certificate management after a domain used by sysadmins globally to test connectivity to Microsoft 365 started generating untrusted connection warnings in browsers on Monday. The connectivity.office.com domain a widely relied-upon tool for …

DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 15, 2026 The open-source DPAPISnoop tool has been enhanced to extract CREDHIST entries, enabling offline cracking of historical Windows credentials and deeper insight into password patterns. Lefteris Panos, Security Consultant at LRQA Red Team, said the update adds CREDHIST …

SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 15, 2026 Threat intelligence sources have reported that the threat actor group SHADOWBYT3$ has allegedly breached Nintendo, claiming to have exfiltrated approximately 859 MB of sensitive internal data. The incident, first observed on June 13, 2026, remains unverified at …