Data Breaches
Nissan Oracle PeopleSoft Campaign Reportedly Targeted 100 Organizations
One confirmed victim, a reported 99 more not yet named — Oracle PeopleSoft customers stay in patch-verification posture this week.
Actionable insights into the global threat landscape. Analysis of TTPs, Indicators of Compromise (IoCs), and emerging attack patterns.
Data Breaches
One confirmed victim, a reported 99 more not yet named — Oracle PeopleSoft customers stay in patch-verification posture this week.
Vulnerabilities
A critical remote monitoring and management vulnerability is under active exploitation to deliver an infostealer that hunts cloud and AI development credentials — and it is now on CISA's KEV list.
Threat Intelligence
Browser-extension enforcement action at scale from Microsoft. The company pulled 119 Edge add-ons that concealed payloads inside image and font files, with a combined install base reported at up to 2.6 million, and suspended the developer accounts behind them.
Supply Chain Attack
Another JavaScript-ecosystem supply-chain disclosure puts developer-secret rotation and GitHub Actions auditing back at the top of the defender to-do list — this time as a fresh wave of the ongoing Miasma cluster.
Nation-State Cyber Threats
Another Russia-linked backdoor lands on defenders' desks for review. Google Threat Intelligence Group and Mandiant have detailed STOCKSTAY, a .NET implant Turla has deployed against Ukrainian government and military networks since at least 2022.
Cybercrime
A retrospective frame on the most consequential law-enforcement effort against cybercrime infrastructure, as Operation Endgame's coordinators recast a string of 2026 takedowns as one sustained assault on the criminal supply chain.
Data Breaches
An Indian industrial-sector confirmation — sector-advisory work for the week. Tata Electronics says a recent incident hit some of its systems while an extortion group leaks data it claims to have stolen, putting manufacturing and supply-chain risk back in focus.
Supply Chain Attack
Supply-chain audit work for organizations using GitHub-hosted CI/CD: a research firm found a recurring pull-request handling and workflow-permission pattern that left 300-plus repositories open to attacker-controlled code execution.
Vulnerabilities
A two-month exposure window prior to the vendor advisory — defenders' SD-WAN posture review continues as Mandiant's analysis of the root-access zero-day lands.
Cybercrime
Operation Endgame's latest phase takes out Amadey and StealC's shared infrastructure, with Europol and Microsoft reporting 326 servers actioned, 142 domains seized, and roughly 27 million stolen credentials recovered.
Cybercrime
Another individual-conviction milestone in the Scattered Spider law-enforcement track: two alleged members admitted unauthorised access to Transport for London's network on the opening day of their trial, with sentencing set for July.
Cybercrime
Operation Endgame's multi-month coordinated action takes down another major distribution backbone, seizing more than a hundred servers and remediating nearly 15,000 compromised WordPress sites worldwide.