Here is the most recent Cybersecurity news for the past week:
πͺ±Keyv-Linked npm Worm Poisons Hundreds of Open-Source Packages
A malicious release of the widely used Keyv npm library triggered a supply chain attack that spread to more than 350 JavaScript packages. The worm targeted development environments, harvesting developer credentials and authentication tokens from tools including Claude Code and Visual Studio Code.
https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html
π Brinks Home Discloses Data Breach as ShinyHunters Leaks Stolen Files
Brinks Home confirmed a cybersecurity incident after the ShinyHunters extortion group published more than 41 GB of stolen internal data. While customer monitoring services remained operational, administrative IT systems containing customer and corporate information were compromised.
https://www.securityweek.com/brinks-home-discloses-data-breach-as-hackers-leak-files/
πBiotech Giant Amgen Reports Cloud Data Breach Exposing Patient Information
Amgen disclosed that attackers accessed multiple cloud environments hosted by third-party providers, exposing proprietary business information, research data, and protected health information (PHI). The incident highlights the growing importance of securing cloud-hosted environments and third-party relationships.
https://www.bleepingcomputer.com/news/security/amgen-says-cloud-data-breach-exposed-patient-health-proprietary-info/
βοΈRussian ‘Laundry Bear’ Hackers Exploit Exchange OWA Zero-Day
The Russian state-sponsored threat group known as Void Blizzard is actively exploiting a zero-day vulnerability in Outlook Web Access to deploy persistent malware and maintain long-term access to targeted government, defense, and telecommunications organizations.
https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access/
πCisco Warns of Firewall Management Zero-Day Exploitation
Cisco issued an urgent advisory for a high-severity vulnerability affecting Secure Firewall Management Center. Attackers are exploiting built-in credentials in combination with additional flaws to gain unauthorized administrative access to security infrastructure.
https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/
|
|



