Keyv npm Worm & Brinks Home Breach – Weekly News Roundup

Here is the most recent Cybersecurity news for the past week:

πŸͺ±Keyv-Linked npm Worm Poisons Hundreds of Open-Source Packages
A malicious release of the widely used Keyv npm library triggered a supply chain attack that spread to more than 350 JavaScript packages. The worm targeted development environments, harvesting developer credentials and authentication tokens from tools including Claude Code and Visual Studio Code.
https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html

🏠Brinks Home Discloses Data Breach as ShinyHunters Leaks Stolen Files
Brinks Home confirmed a cybersecurity incident after the ShinyHunters extortion group published more than 41 GB of stolen internal data. While customer monitoring services remained operational, administrative IT systems containing customer and corporate information were compromised.
https://www.securityweek.com/brinks-home-discloses-data-breach-as-hackers-leak-files/

πŸ’ŠBiotech Giant Amgen Reports Cloud Data Breach Exposing Patient Information
Amgen disclosed that attackers accessed multiple cloud environments hosted by third-party providers, exposing proprietary business information, research data, and protected health information (PHI). The incident highlights the growing importance of securing cloud-hosted environments and third-party relationships.
https://www.bleepingcomputer.com/news/security/amgen-says-cloud-data-breach-exposed-patient-health-proprietary-info/

βœ‰οΈRussian ‘Laundry Bear’ Hackers Exploit Exchange OWA Zero-Day
The Russian state-sponsored threat group known as Void Blizzard is actively exploiting a zero-day vulnerability in Outlook Web Access to deploy persistent malware and maintain long-term access to targeted government, defense, and telecommunications organizations.
https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access/

πŸ”Cisco Warns of Firewall Management Zero-Day Exploitation
Cisco issued an urgent advisory for a high-severity vulnerability affecting Secure Firewall Management Center. Attackers are exploiting built-in credentials in combination with additional flaws to gain unauthorized administrative access to security infrastructure.
https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/

newsletter signup

Our goal? To deliver the best cybersecurity insights you can read inΒ five minutes or lessΒ β€” straight to your inbox, once a week.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

newsletter signup

Our goal? To deliver the best cybersecurity insights you can read inΒ five minutes or lessΒ β€” straight to your inbox, once a week.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.