惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
Scott Helme
Scott Helme
爱范儿
爱范儿
WordPress大学
WordPress大学
博客园 - 三生石上(FineUI控件)
阮一峰的网络日志
阮一峰的网络日志
博客园 - Franky
V
V2EX
腾讯CDC
博客园_首页
博客园 - 司徒正美
酷 壳 – CoolShell
酷 壳 – CoolShell
T
Tailwind CSS Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
小众软件
小众软件
J
Java Code Geeks
大猫的无限游戏
大猫的无限游戏
月光博客
月光博客
Microsoft Azure Blog
Microsoft Azure Blog
B
Blog
雷峰网
雷峰网
Stack Overflow Blog
Stack Overflow Blog
IT之家
IT之家
罗磊的独立博客
Recorded Future
Recorded Future
博客园 - 聂微东
O
OpenAI News
S
Secure Thoughts
Hacker News: Ask HN
Hacker News: Ask HN
S
Schneier on Security
Hacker News - Newest:
Hacker News - Newest: "LLM"
Y
Y Combinator Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
Project Zero
Project Zero
宝玉的分享
宝玉的分享
K
Kaspersky official blog
N
Netflix TechBlog - Medium
T
The Exploit Database - CXSecurity.com
Google Online Security Blog
Google Online Security Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Webroot Blog
Webroot Blog
云风的 BLOG
云风的 BLOG
Simon Willison's Weblog
Simon Willison's Weblog
C
Check Point Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
L
LINUX DO - 热门话题
美团技术团队
L
Lohrmann on Cybersecurity

GovInfoSecurity.com RSS Syndication

On Demand | Regulation Didn’t Change, Your Identity Landscape Did On Demand | Weaving Agentic AI into the SOC: A Practical Playbook for Operationalizing and Scaling Autonomy Why Periodic Pentesting Can’t Keep Up And What Security Leaders Are Doing Instead Claude Mythos 5 Can Build Exploits But Can't Power Campaigns AI Is Reshaping Cybersecurity Training Priorities Health Cyberthreat Sharing Is Advancing But Gaps Persist Are Small Models Closing the Gap on Frontier AI Cyber Tools? Government info security news, training, education Government info security news, training, education Government info security news, training, education Government info security news, training, education Beyond the Inbox: Defending Against AI-Enabled Social Engineering Webinar | 6 Layers Standing Between Your Enterprise and AI Risk Webinar | 6 Layers Standing Between Your Enterprise and AI Risk Webinar | Securing the Agentic Enterprise: An Integrated Policy Framework for Enterprise AI Security How AI Governance Protects Patient Care and Sensitive Data Why Hospitals Must Rethink Cyber Resilience The Privacy Risks of Embedded, Shadow AI in Healthcare Why Election Systems Are Now a Persistent Cyber Target Anthropic Submits Pre-IPO SEC Filing, Leads Market Cap Fight AI Agents Are the New Insiders Demystifying Claude: Signal vs. Speculation German Court: Google Liable for AI Summaries DOJ, FBI Seize 13 Domains in Chinese Recruitment Op A Security Gets $37M to Thwart Weaponized AI With Automation Breach Roundup: CISA Says Agencies Should 'Patch Smarter' Google Sues Chinese Phishing Service Over Gemini Abuse Policy as Code: From Documents to Machine Intelligence Anthropic Limits on OT Access to Mythos Draw Criticism Ozempic Drug Maker Loses Clinical Trial Data in Hack ISMG Editors: Anthropic Unleashes Claude Mythos 5 ISACA Survey: AI Adoption Is Rising, Visibility Is Not Webinar | Frontier AI and Identity Security in Financial Services US Pulls the Plug on Anthropic's Top AI Models US Anthropic Export Controls Sparks Sharp EU Reaction 1Password Buys Apono to Expand AI Access Governance Why Banks Must Align Stakeholders Before Scaling AI Geopolitics Is Now a Cybersecurity Problem Why AI Defenses Fail Without Data and Identity Fundamentals Labcorp Agrees to Pay $35M to Settle AMCA Data Breach NewCore Launches With $66M to Rebuild Identity for AI Agents GovSec Summit USA 2026: Cyber Resilience Amid Fiscal Reality How FDA Mythos Shutdown Contains a Message: Don ShinyHunters Hits Universities Via Oracle Zero-Day How FDA US FCC Eases Router Ban for Cable ISPs Chinese Hacking Firm Upgrades With New Windows Backdoor South Korea Fines Coupang $409M Over Massive Data Breach Cyber Resilience Summit Dallas Prioritizes Risk Management Hacker: Restore Fable and Mythos Access, Cybersecurity Leaders Urge Live Webinar | Behind Dell’s AI Infrastructure Performance Rokarolla Android Banking Trojan Enables Device Takeover Ent Raises $100M to Reinvent Endpoint Security for AI Era The AI Accountability Gap CIOs Can Chinese Espionage Actor Abuses Email Rules to Steal Research Data AWS Unveils Continuum to Fight Vulnerability Backlog Quantum-Safe Cryptography Isn SpaceX Bets Big on AI Coding With $60B Cursor Deal Heart Monitoring Firm Tells SEC Hackers Stole Sensitive Data Mastra AI Framework Poisoned in npm Supply-Chain Attack Cyberspace Locked in a Nation-State Contest, Says NCSC CEO Webinar | The Future of SASE: Top 5 Predictions and Trends The Gentlemen Ransomware Gang Standardizes EDR Killing Attackers Steal Salesforce Data From Klue Battlecards Users CISA Urges OT Resilience in Dark Remarks About Cyberattacks Crime Gang Sells Access to 74,000 Fortinet Firewall Devices JPMorgan Pulls Anthropic Claude Access in Hong Kong Webinar | From SBOM to Submission: Operationalizing CRA Vulnerability Handling 6 Ways to Contain Enterprise Risk in Model Context Protocol AI Inherits People Accenture Buys Majority Stake in Dragos in $4.2B Deal Multimillion-Dollar Settlement Reached in MCNA Dental Hack Addressing Quantum Readiness in Healthcare Security Cybercrime Initial Access Service SocGholish Disrupted Experts Warn of Klue Confirms OAuth Token Theft Led to Salesforce Data Heist From Reflection to Shadow: AI, Us and the Space in Between ISMG Editors: Cyber Backlash Over the US Ban on Anthropic AI France and Germany Boost Digital Sovereignty Push North Korean IT Workers Try, Try, Try Again HIPAA Europe Seeks to Advance 6G Security, Privacy No Zero-Day Tied to 80,000 Harvested Fortinet Credentials Is It Time to Put Some Teeth in Post-Quantum Guidelines? New AI Model Aims to Transform Behavioral Health Lawsuits Already Getting Filed in Drug Maker Sakana AI Bets on Agent Orchestration Over Frontier Models OpenAI Lets Cyber Vendors Embed GPT-5.5 in Defenses Trump Executive Order Accelerates Post-Quantum Security Push AryStinger Botnet Converts Legacy Routers to Global Proxies North Korean Hackers Poison Mastra AI Framework Live Webinar | Proactive Cyber Defense: Identifying Risk Before It Becomes an Incident The New Boardroom Mandate: Building Barriers to Limit Cyber Impact 2 British Men Plead Guilty to Transport for London Hacks Xsolis Hack Affecting 1.4M Raises AI Vendor Risk Concerns FortiBleed Is Why Security Firm Varonis Is Eyeing a Sale to Private Equity
Breach Roundup: ShinyHunters Leaks 26M MSG Records
Pooja Tikekar · 2026-06-19 · via GovInfoSecurity.com RSS Syndication

Cybercrime , Fraud Management & Cybercrime , Incident & Breach Response

Also, Arch Linux Attack, Estonia Quarantines Russian Emails, Joomla Flaw (@PoojaTikekar) • June 18, 2026    
Breach Roundup: ShinyHunters Leaks 26M MSG Records
Image: Shutterstock/ISMG

Every week, ISMG rounds up cybersecurity incidents and breaches around the world. This week, extortion gang ShinyHunters published alleged Madison Square Garden data. U.S. Sen. Mark Warner questioned whether staffing cuts are weakening CISA's support for state and local governments. A sprawling supply-chain attack compromised more than 1,500 Arch Linux packages, Australian sugar producer Mackay Sugar advanced recovery efforts after a ransomware attack and Microsoft faced scrutiny after a certificate lapse disrupted a key Microsoft 365 diagnostic site. Estonia will quarantine Russian emails while Novo Nordisk grappled with competing data theft claims from two cybercrime groups. Belarus-linked hackers targeted personal Gmail accounts in Poland, CISA ordered agencies to patch an actively exploited Joomla flaw and Kodak investigated a data breach claim. Researchers exposed the infrastructure behind a large-scale phishing operation.

See Also: Know Thy Enemy: Threats to Cyber Resilience

ShinyHunters Publishes Madison Square Garden Data After Ransom Deadline Passes

Digital extortion gang ShinyHunters published what it claims is stolen Madison Square Garden Entertainment data after the organization allegedly declined to pay ransom.

The group claimed MSG - home of New York Knicks, which just won its first NBA championship in 53 years - "failed to reach an agreement" despite "all the chances and offers we made," according to a posting on its leak site. The leak went public one day after the June 15 negotiation deadline expired.

The leaked dataset purportedly contains more than 26 million records, including ticketing operations, customer account details, and internal corporate documents tied to both the Knicks and New York Rangers hockey franchise. ShinyHunters said the intrusion occurred on June 5.

The group posted more than 42 gigabytes of data on its leak site Tuesday. Files referencing Knicks-related personalities alongside internal categorization fields includes address, claim to fame, cost of talent and direct contact information for those individuals or their representatives. Files indicate that actor Ben Stiller is categorized as "low risk" by MSG, while rapper A Boogie wit da Hoodie is categorized as "high risk."

A lawsuit filed Tuesday alleges that hackers accessed sensitive visitor data through MSG's surveillance and facial recognition systems. Plaintiff Carlos Avalos claims his personal information was collected when he attended a concert at MSG in September 2025 and alleges the company has not yet notified those affected.

ShinyHunters, active since at least 2019, is linked to multiple high-profile data breaches, including incidents affecting Okta, AT&T and Tokopedia. Its typical approach involves stealing sensitive data and using so-called "pay-or-leak" extortion tactics to pressure victims into paying.

The latest disclosure is the second major security incident to affect MSG in under a year. In 2025, the Cl0p ransomware group exploited an Oracle E-Business Suite vulnerability, exposing names and Social Security numbers for at least 38,393 individuals and ultimately leaking more than 210GB of archived MSG files after the organization declined to pay.

Warner Questions CISA's Ability to Support US States After Staff Cuts

Sen. Mark Warner, D-Va., is pressing the U.S. Cybersecurity and Infrastructure Security Agency for details on staffing cuts and vacancies, warning that workforce reductions may be weakening cyber support for state and local governments.

In a Tuesday letter to Acting CISA Director Nick Andersen, Warner requested data on vacancies, employee departures, regional office staffing and service delivery metrics for CISA headquarters and regional offices.

Cuts enacted to the agency since the start of the Trump administration, as well as the White House's decision to yank funding from the Multi-State Information Sharing and Analysis Center, demonstrate "a dangerous underestimation of the threats facing our nation from adversaries and criminals who seek to destabilize our national security, economy, public health and safety," Warner wrote.

Half of the agency's 10 regional directors are serving in acting roles, Warner noted. He asked CISA to disclose whether staff reductions have affected vulnerability scans, incident response, risk assessment, response times and service requests.

In separate letters to Homeland Security Secretary Markwayne Mullin and U.S. governors, Warner said many local governments cannot afford to pay MS-ISAC subscription fees. He said the change weakens cyber defenses at a time when state and local organizations remain frequent ransomware targets.

Supply-Chain Attack Hits More Than 1,500 Arch Linux Packages

A large-scale software supply-chain attack compromised more than 1,500 packages in the Arch User Repository, with attackers hijacking abandoned projects and modifying them to install malicious npm dependencies that deploy credential-stealing malware, security researchers at Sonatype found.

In the campaign dubbed "Atomic Arch," attackers targeted orphaned AUR packages, taking over legitimate but unmaintained projects and altering their pkgbuild files to fetch a malicious npm package called atomic-lockfile during installation. Analysis showed the payload included capabilities for credential theft, stealth, anti-debugging and potential data exfiltration. A second wave of attacks later shifted to Bun-based installation paths using additional malicious packages.

Arch Linux said it experienced a surge of malicious package adoptions and updates in the repository and urged users to carefully review pkgbuild and install script changes before updating packages. The project temporarily restricted several repository functions, including new account registrations, while maintainers investigated and removed malicious commits.

Researchers said the malware was designed to harvest credentials and developer secrets, with some analyses indicating support for eBPF-based functionality that could help attackers evade detection or establish persistence on infected Linux systems.

Mackay Sugar Advances Recovery Efforts Following Cyberattack

Australian sugar producer Mackay Sugar said Wednesday it was making significant progress restoring systems and preparing for staged restart of crushing operations following a cyberattack that disrupted milling activities and halted cane harvesting across its Queensland operations.

Ransomware group "The Gentlemen" claimed responsibility for the attack on the company, Australia's second-largest sugar producer. The group posted the company on its leak site, but no stolen data had been published yet. The attack caused many of the 1,300 farms that supply Mackay Sugar to pause harvesting," reported Australian public broadcaster ABC.

Microsoft Site Hit by Certificate Lapse

Microsoft's connectivity testing portal for Microsoft 365 began throwing browser security warnings after a TLS certificate expired and went unrenewed for more than a day.

The affected site, connectivity.office.com, is used by IT professionals and network administrators to test and troubleshoot network connectivity to Microsoft's 365 services and verify that firewalls are not blocking access to Microsoft's cloud infrastructure. Visitors to the site were met with browser alerts flagging an invalid security certificate after the certificate expired on June 14. The issue reportedly persisted for roughly 35 hours before being addressed.

The lapse disrupted access to a diagnostic tool that administrators rely on to investigate connectivity issues, confirm firewall configurations and run network health checks.

Estonia to Quarantine Emails From Russian Servers Over Cybersecurity Risks

Estonia will begin routing emails sent from Russian .ru domains into quarantine before they reach public-sector inboxes, local media ERR reported. The measure takes effect Aug. 31.

Justice and Digital Affairs Minister Liisa Pakosta said the decision follows a continuous increase in malicious emails arriving through Russian servers since 2022. Legitimate messages will still be delivered but may require additional verification, introducing delays while reducing exposure to phishing and malware threats.

The Estonian Information System Authority warned in 2022 that Russian email services are frequently used in phishing campaigns and malware distribution. Pakosta said communications sent through Russian-hosted services could be accessible to Russian authorities.

Novo Nordisk Hit by Dual Breach Claims

Danish pharmaceutical maker Novo Nordisk is dealing with a double dose of serious breach headaches.

Less than 24 hours after cybercrime gang FulcrumSec began on Tuesday leaking data from what it claims is a 1.3 terabyte trove of stolen Novo Nordisk proprietary data, a second group - dubbed TheUSERS007, told Databreaches.net that it too recently stole a set of "crown jewel" data from the Danish drug maker (see: Ozempic Drug Maker Loses Clinical Trial Data in Hack).

TheUSERS007 claimed it gained access to Novo Nordisk's IT systems between June 5 and June 7 and used "venomware," which the gang described as "a self-learning, adaptive artificial intelligence engine" to surgically extract the drug company's intellectual property.

The threat actor told Databreaches.net that it demanded Novo Nordisk pay a $50 million ransom for the data the group allegedly stole, including 16.7GB of trained AI weights, full source code, SSH host keys, a 500-MB proprietary dataset and more.

Novo Nordisk on Tuesday told ISMG that it was aware of claims that data copied externally from its systems without authorization has been published online.

GhostWriter Shifts Focus to Gmail Accounts in Poland

Poland's national computer emergency response team warned that the Belarus-linked hacking group GhostWriter is targeting personal Gmail accounts belonging to public figures and their families.

Attackers have launched phishing campaigns since March aimed at government officials, journalists, researchers, public administration and law enforcement personnel and their social circles.

CERT Polska said GhostWriter is one of the most active state-sponsored threat groups targeting Poland. Researchers said they have observed new phishing domains appearing almost daily in recent weeks.

The phishing operations are designed to steal login credentials and two-factor authentication codes, enabling attackers to access victims' email accounts. Once inside, the hackers search for sensitive documents, contact networks and linked online accounts that can be used to identify additional targets or hijack social media profiles.

Also tracked as UNC1151 and Storm-0257, GhostWriter is linked to Belarusian intelligence services and has conducted cyberespionage and influence operations targeting Poland, Ukraine and Belarusian opposition groups.

CISA Flags Actively Exploited Joomla Flaw

The U.S. Cybersecurity and Infrastructure Security Agency ordered federal agencies to patch a critical vulnerability in the Joomla Content Editor plugin after confirming active exploitation in the wild.

The flaw, tracked as CVE-2026-48907, enables unauthenticated attackers to upload and execute malicious PHP code through improperly secured editor profiles. The vulnerability affects Joomla sites running the JCE WYSIWYG editor plugin and can be exploited using low-complexity attacks.

The issue was patched earlier this month in JCE Pro 2.9.99.6. The JCE security team urged users to update immediately, warning that public exploit code is available and attacks are being automated.

Researchers also cautioned that installing the update only blocks further exploitation and does not remove malware or backdoors already deployed on compromised systems.

Kodak Investigates Data Breach Claim

Kodak is investigating a cybersecurity incident after an unauthorized third party gained temporary access to a limited amount of company data, Kodak said.

The Rochester, New York-based imaging and printing firm said it has engaged external cybersecurity experts to determine what information was accessed or copied and is working with law enforcement. "We are confident the incident was limited in scope and has been contained and that there is no threat to our systems or operations as a result of the incident," it said in a prepared statement.

The company has not attributed the breach or disclosed how attackers gained access. The ShinyHunters extortion group claimed responsibility. On its darkweb leak site, the group alleged it stole more than 2.2 million records containing customers' personally identifiable information and internal corporate data, threatening to publish the data if its demands are not met.

Researchers Details Infrastructure Behind Poisson Campaign

Researchers at Cato CTRL found the workings of a cybercriminal operation dubbed "Operation Poisson" after discovering an exposed server that provided access to the threat actor's infrastructure and operational data.

According to the firm, the server contained phishing kits, credential logs, configuration files, victim information and communications related to the operation. Analysis of the data showed that the actor primarily targeted users through phishing campaigns designed to steal account credentials and session data.

Researchers identified infrastructure used to host phishing pages, manage compromised accounts and collect stolen information. The operation relied on automation to process harvested credentials and track victims. Logs recovered from the server revealed thousands of credential theft attempts and provided visibility into how victims were funneled through phishing workflows.

The exposed data also included details about domains, hosting infrastructure and backend management systems used to support the campaigns. Researchers said the operator maintained organized records of stolen credentials and victim activity, suggesting a structured approach to managing the operation.

Other Stories From This Week

With reporting from ISMG's Anviksha More in Mumbai and Marianne Kolbasuk McGee in the Boston exurbs.