Cybersecurity Daily

Generated: 2026-06-23 03:01 UTC

CRITICAL

CRITICAL SECTION

No items scoring 10 today.

CISA KEV (Known Exploited Vulnerabilities)

No CISA KEV items in the last 14 days.

RANSOMWARE VICTIMS (DLS Monitoring)

Unknown: Huntress, HDS (Hdscorp), Gms-net, Cqcrm, Cbassociations, bits-pilani.ac.in, mihana-v.com, belpointeasset.com \ belpointe.com, ehg.bayern, Schumacher Homes, EON Meditech Pvt, graymont.com, eggetttax.ca, sterlinggloballtd.com, Ntd Apparel, NEW PRINZ EUGEN SITE [NOT A CASE FILE], Aerospace & Advanced Composites GmbH, Central Bank of Libya, Union Tractor, NTP B.V. Civil Engineering Construction, Kochs GmbH, NationsBuilders Insurance Services

NEWS

[8] What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks (SecurityWeek) 14 <p>Groups like ShinyHunters are demonstrating that attackers do not necessarily need malware or zero-day exploits to cause massive damage.</p> <p>The post <a href="https://www.securityweek.com/what-the-latest-shinyhunters-breaches-reveal-about-modern-cyberattacks/">What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>

[7] North Korean Hackers Blamed for Mastra NPM Supply Chain Attack (SecurityWeek) 14 <p>A malicious dependency the attackers added to over 140 Mastra packages fetches a payload targeting cryptocurrency extensions.</p> <p>The post <a href="https://www.securityweek.com/north-korean-hackers-blamed-for-mastra-npm-supply-chain-attack/">North Korean Hackers Blamed for Mastra NPM Supply Chain Attack</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>

[6] ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack (TheHackerNews) 14 Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code. "Attackers compromised the vendor's build and distribution pipeline, injecting backdoor code into Pro plugin releases distributed through official licensed update channels," Wordfence said in an analysis

KEV

[6] Hundreds of AI-powered iOS apps found exposing credentials (HelpNetSecurity) 14 <p>Mobile app developers are packing AI features into everything from writing assistants to productivity tools and lifestyle apps. New research shows that securing access to those services remains a challenge. LLM API credential leakage via network traffic interception (Source: Research paper) Researchers from Wake Forest University analyzed 444 iOS applications with LLM features and found 282 that exposed exploitable credentials or backend access mechanisms. The affected apps covered 13 categor

[5] ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More (TheHackerNews) 14 It’s Monday again. This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools, and mobile malware asking for way too much control. The annoying part is how little of this feels new. Weak credentials, sketchy downloads, browser extensions with too much access, and WordPress sites are used to push more

SUMMARY

Total new items: 53; Critical: 0; Ransomware groups active: 1; Top CVEs to patch urgently: None.

Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

RANSOMWARE VICTIMS

NEWS

SUMMARY