Risk
-
Medtronic confirms network breach after hackers claim theft of 9 million records
Medtronic said hackers breached corporate IT systems and may have accessed personal data after ShinyHunters claimed theft of more than 9 million records and terabytes of internal data.
-
PhantomCore linked to attacks on TrueConf servers in Russia
PhantomCore has been tied to attacks on TrueConf servers in Russia since September 2025, using three vulnerabilities to run commands remotely and move deeper into victim networks, according to a technical analysis by Positive Technologies.
-
Researchers flag 73 fake VS Code extensions tied to GlassWorm campaign
Researchers flagged 73 fake Visual Studio Code extensions on Open VSX tied to the GlassWorm campaign. Six were confirmed malicious, while the rest were sleeper packages designed to build trust before delivering malware.
-
Fake CAPTCHA scam used SMS charges, Keitaro abused in 120 campaigns
Researchers said fake CAPTCHA pages have been used since at least 2020 to trigger costly international SMS traffic, while more than 120 other campaigns abused Keitaro TDS for malware, crypto theft and investment scams.
-
Itron says unauthorized party accessed internal systems in cyberattack
Itron said an unauthorized third party accessed some internal systems in a cyberattack and that it blocked the activity after detecting it on April 13, 2026. The company said business operations were not materially disrupted and customer systems were not affected.
-
Tropic Trooper campaign uses trojanized SumatraPDF to deploy AdaptixC2
A campaign tied to Tropic Trooper is using a trojanized SumatraPDF reader to deploy AdaptixC2 and, in some cases, Visual Studio Code tunnels for remote access against targets in Taiwan, South Korea and Japan.
-
SentinelOne finds old malware that may have aimed to sabotage engineering software
SentinelOne says it found old malware that may have been built to sabotage engineering and physics simulation software. The sample appears to predate Stuxnet by years and may have targeted precision calculation tools used in several technical fields.
-
UNC6692 Uses Microsoft Teams Help Desk Impersonation to Push Custom Malware
UNC6692 used Microsoft Teams help desk impersonation, email bombing and a custom malware chain to target corporate users, according to Mandiant. The activity included credential harvesting, remote access, tunneling and later-stage network movement.
-
Bitwarden CLI hit by npm supply chain compromise in Checkmarx-linked campaign
Bitwarden said its CLI package was briefly compromised on npm on April 22, 2026, in a supply chain attack that targeted developer secrets and CI/CD credentials through version 2026.4.0.










