π¨ Supply chain attack: 141 packages in the npm mastra scope were republished overnight to ship a remote access trojan.
The source code was never touched. The attacker just added one dependency, easy-day-js, that downloads persistent malware on install.
https://safedep.io/mastra-npm-scope-takeover-supply-chain-attack/
The source code was never touched. The attacker just added one dependency, easy-day-js, that downloads persistent malware on install.
https://safedep.io/mastra-npm-scope-takeover-supply-chain-attack/
π€―2
βΌοΈπ¨ BREAKING: 320,000 Fortinet firewall devices have been targeted in a campaign that has been dubbed 'FortiBleed'. Attackers were able to confirm 75,000 working credentials against the admin and SSL VPN interfaces.
The victims include really big names like Samsung, Oracle, Spotify, Sony, and more.
The data was first surfaced by researcher Volodymyr "Bob" Diachenko and analyzed by Hudson Rock and SOCRadar. The operation runs as a self-feeding loop. Attackers scan the internet for exposed Fortinet devices, then test each one against a curated list of passwords leaked from earlier Fortinet breaches and infostealer logs. Every successful login gets recorded into a verified database. They then turn each compromised box into a listening post, sniffing the traffic passing through the firewall to harvest fresh credentials, which go straight back into the scanner.
The scale is large. The group ran an estimated 1.16 billion credential attempts against more than 320,000 FortiGate targets, plus 2.1 billion brute-force tries against 160,000 MSSQL servers. In the deeper intrusions they intercept SSL VPN authentication hashes, crack them on a dedicated 45-GPU cluster, and move into internal Active Directory.
Diachenko confirmed full network compromises in Japan, Taiwan, Vietnam, Iraq, and Turkey, including a Turkish NATO defense contractor that had classified defense documents stolen.
If you run Fortinet, act now: rotate every VPN and admin credential, enforce MFA on all external gateways, restrict management access to approved sources, segment internal networks, and audit gateway logs for unusual logins. Hudson Rock has a free domain lookup at hudsonrock.com/fortinet.
Data surfaced via the Hunt Intelligence, Inc. feed.
The victims include really big names like Samsung, Oracle, Spotify, Sony, and more.
The data was first surfaced by researcher Volodymyr "Bob" Diachenko and analyzed by Hudson Rock and SOCRadar. The operation runs as a self-feeding loop. Attackers scan the internet for exposed Fortinet devices, then test each one against a curated list of passwords leaked from earlier Fortinet breaches and infostealer logs. Every successful login gets recorded into a verified database. They then turn each compromised box into a listening post, sniffing the traffic passing through the firewall to harvest fresh credentials, which go straight back into the scanner.
The scale is large. The group ran an estimated 1.16 billion credential attempts against more than 320,000 FortiGate targets, plus 2.1 billion brute-force tries against 160,000 MSSQL servers. In the deeper intrusions they intercept SSL VPN authentication hashes, crack them on a dedicated 45-GPU cluster, and move into internal Active Directory.
Diachenko confirmed full network compromises in Japan, Taiwan, Vietnam, Iraq, and Turkey, including a Turkish NATO defense contractor that had classified defense documents stolen.
If you run Fortinet, act now: rotate every VPN and admin credential, enforce MFA on all external gateways, restrict management access to approved sources, segment internal networks, and audit gateway logs for unusual logins. Hudson Rock has a free domain lookup at hudsonrock.com/fortinet.
Data surfaced via the Hunt Intelligence, Inc. feed.
π5π₯3β€2
π¨ An active campaign malware on Steam is hiding payloads inside Wallpaper Engine desktop wallpapers.
Dozens of infected packages, some with tens of thousands of downloads, drop the DarkComet backdoor plus Lumma and Vidar infostealers to steal Steam accounts.
https://www.kaspersky.com/about/press-releases/kaspersky-discovered-a-malware-campaign-targeting-steam-users-through-infected-wallpaper
Dozens of infected packages, some with tens of thousands of downloads, drop the DarkComet backdoor plus Lumma and Vidar infostealers to steal Steam accounts.
https://www.kaspersky.com/about/press-releases/kaspersky-discovered-a-malware-campaign-targeting-steam-users-through-infected-wallpaper
π8π3π2β€1π€ͺ1
βΌοΈπ¨ A critical Joomla Content Editor vulnerability is under active attack and rated CVSS 10.0. Joomla is used by 1.2% of all websites on the internet.
The vulnerability, CVE-2026-48907: an unauthenticated attacker can create an editor profile, upload PHP, and take full control of the site.
CISA and Italy's CSIRT have both issued alerts.
The vulnerability, CVE-2026-48907: an unauthenticated attacker can create an editor profile, upload PHP, and take full control of the site.
CISA and Italy's CSIRT have both issued alerts.
π¨ An AI-enabled Dutch man was sentenced to 2.5 years in prison for using deepfakes to open 47 bank accounts. The man used ChatGPT to plan his criminal activity, which included using residential proxies.
He sourced victim photos from social media, older data breaches, and by posing as a landlord on an online marketplace to request ID documents. He then built deepfakes from those photos to beat the bank's facial verification during mobile onboarding.
Border police flagged him carrying multiple bank cards. His phone held dozens of IDs, victim photos, and ChatGPT chats on how to bypass identity verification.
He sourced victim photos from social media, older data breaches, and by posing as a landlord on an online marketplace to request ID documents. He then built deepfakes from those photos to beat the bank's facial verification during mobile onboarding.
Border police flagged him carrying multiple bank cards. His phone held dozens of IDs, victim photos, and ChatGPT chats on how to bypass identity verification.
π€£16π4π2π2β€1π₯1
βΌοΈπ¨ Grok AI was used by the US to help fire more than 2,000 munitions at 2,000 separate targets inside Iran within 96 hours. The disclosure comes from a sworn declaration by Cameron Stanley, the Pentagon's chief digital and AI officer, filed June 15 in the NAACP's lawsuit against xAI in the Northern District of Mississippi. Stanley said the Grok Gov Model, running inside Palantir's Maven Smart System, drove the strikes during Operation Epic Fury, the codename for the war launched on Iran in late February.
The filing was meant to protect xAI's Colossus 2 data center in Memphis, which the NAACP says is illegally polluting Black neighborhoods. The Pentagon argued the site is a matter of national security and named xAI one of only three vendors cleared to run mission-critical operations on classified networks.
The filing was meant to protect xAI's Colossus 2 data center in Memphis, which the NAACP says is illegally polluting Black neighborhoods. The Pentagon argued the site is a matter of national security and named xAI one of only three vendors cleared to run mission-critical operations on classified networks.
π€¬16π5π¨4β€3π₯2π©2π1
π¨ Apple is raising prices across its product line, blaming chip shortages. CEO Tim Cook says the hikes are unavoidable as AI buyers drain memory and storage supply.
π€£14π€¬10π3π€1
βΌοΈ A fully AI-enabled hacker was caught, revealing his full system prompts, which included his resume and his IP address. He had Claude and Codex agents locally and was using them remotely to carry out reconnaissance, exploitation, and data exfiltration activities.
In his sessions, the attacker Injects a "senior red team penetration tester⦠fully authorized" persona.
He might be dumber than you think: The attacker's first jobs for Claude were polishing his resume, then building an automated job application tool. That resume lists his full name, location, schooling, and LinkedIn profile, exposing him as a young man in Addis Ababa, Ethiopia.
Posing as a redteam, the attacker got Claude to suggest and rank ways to profit from the breaches. Claude and Codex blocked most of these, flagging it as illegitimate. He still pulled a list: extortion, data sale, BEC, fund theft, plus attempts to crack a Bitcoin wallet and sell stolen credentials.
Full disclosure: https://research.openanalysis.net/claude/codex/hacking/ai%20hacking/llm/redteam/policy%20violation/2026/06/16/compromised-claude-hacking.html
In his sessions, the attacker Injects a "senior red team penetration tester⦠fully authorized" persona.
He might be dumber than you think: The attacker's first jobs for Claude were polishing his resume, then building an automated job application tool. That resume lists his full name, location, schooling, and LinkedIn profile, exposing him as a young man in Addis Ababa, Ethiopia.
Posing as a redteam, the attacker got Claude to suggest and rank ways to profit from the breaches. Claude and Codex blocked most of these, flagging it as illegitimate. He still pulled a list: extortion, data sale, BEC, fund theft, plus attempts to crack a Bitcoin wallet and sell stolen credentials.
Full disclosure: https://research.openanalysis.net/claude/codex/hacking/ai%20hacking/llm/redteam/policy%20violation/2026/06/16/compromised-claude-hacking.html
π€£21π3β€1π€ͺ1
βΌοΈ BREAKING: Volkswagen has banned GrapheneOS users from using their app. Users are reporting they can't log in or control their car anymore. Users are confused, saying Volkswagen allows their app to be used on End-of-Life Android versions, but not on fully patched GrapheneOS.
https://discuss.grapheneos.org/d/35949-volkswagen-app/50
https://discuss.grapheneos.org/d/35949-volkswagen-app/50
π19π€¬9π€£6π©3