The Oncology Institute has reported a data breach involving a third-party vendor, which has yet to be named. However, speculation points to TriZetto as a potential source of the breach. This incident raises concerns about the security of patient data, as healthcare organizations increasingly rely on third-party vendors to manage sensitive information. The breach could expose personal health information, putting affected patients at risk of identity theft and other privacy violations. As the investigation unfolds, it is crucial for healthcare providers to assess their vendor relationships and ensure that strong security measures are in place to protect patient data.
U.S. state governments are ramping up their cybersecurity efforts to better protect local communities and critical services. Many states are establishing their own cyber defense programs, which include initiatives like cybersecurity clinics and regional security operations centers (RSOCs). These programs aim to reduce costs and enhance the cybersecurity workforce, ultimately improving the resilience of local infrastructures against cyber threats. As of April 2026, states are also looking to share services and centralize procurement to better manage cyber risks. This shift reflects a growing recognition of the importance of state-level involvement in safeguarding against increasing cyber threats.
Hackread – Cybersecurity News, Data Breaches, AI and More
Dutch law enforcement has arrested two individuals involved in running a bulletproof hosting network that facilitated various cybercriminal activities, including disinformation campaigns and evasion of Russian sanctions. Bulletproof hosting refers to web hosting services that protect clients from legal action, allowing them to operate illicit activities with reduced risk of shutdown. This operation is significant as it targets the infrastructure that enables cybercrime and misinformation, which can have widespread effects on public trust and security. The dismantling of such networks is crucial for combating online threats and maintaining the integrity of information. Authorities are working to understand the full extent of the network's operations and its connections to larger cybercriminal organizations.
Anthropic's Mythos has identified around 23,000 potential vulnerabilities across 1,000 open-source software (OSS) projects. Among these, many have been confirmed as critical or high-severity issues, suggesting a significant risk to software security. As this number is expected to rise, it poses a serious concern for developers, companies, and users relying on these OSS projects. The findings highlight the need for heightened scrutiny and proactive measures to secure software environments. Open-source projects often rely on community contributions, which can lead to oversight in vulnerability management, making this situation particularly urgent.
Recently, researchers discovered that malicious tags were injected into Laravel-Lang packages, a popular library used in web development. Within a 15-minute window, these tags created backdoors that could exfiltrate continuous integration (CI) secrets, potentially putting many developers and projects at risk. This incident is particularly concerning because it affects a widely used package, meaning that numerous applications relying on Laravel-Lang could be compromised. Developers using these packages need to be vigilant and review their code for any unauthorized changes. The incident serves as a reminder of the importance of securing third-party libraries and regularly monitoring for vulnerabilities.
A newly discovered zero-click attack is targeting WhatsApp accounts on iPhones running iOS 16, allowing attackers to take control of accounts without any user interaction or warning. This means that users can find their accounts sending unauthorized messages, often asking contacts for money transfers, without realizing they’ve been compromised. The attack is particularly concerning because it does not require any linked devices, making it harder for users to identify or prevent the intrusion. As this vulnerability is actively exploited, users of WhatsApp on iOS 16 need to be vigilant and take precautions to protect their accounts. This incident highlights the ongoing challenges of mobile security and the importance of being cautious about unsolicited messages and requests.
Fraudsters are targeting Formula 1 fans with various scams, including fake streaming services and counterfeit merchandise. The Bitdefender Cybersecurity Grand Prix Fan Threat Index reveals that these scams are increasingly common, especially during major racing events where fan interest peaks. Unsuspecting fans may fall victim to these schemes, losing money and personal information. The article emphasizes the importance of awareness and vigilance among fans, encouraging them to verify the legitimacy of online services and products before making purchases. With the growing popularity of F1, these scams pose a significant risk to the fan community, making cybersecurity education essential.
Dutch authorities have arrested two individuals and confiscated 800 servers linked to Stark Industries, a hosting provider allegedly involved in facilitating cyberattacks and disinformation campaigns. The investigation revealed that the suspects supported operations believed to be aligned with Russian interests. This crackdown highlights the ongoing efforts by law enforcement to disrupt networks that play a role in spreading false information and conducting cyber operations. As these incidents can undermine public trust and influence political landscapes, the authorities' actions aim to mitigate these risks and hold those responsible accountable. The seizure of such a large number of servers indicates the scale of the operations being targeted.
Hackread – Cybersecurity News, Data Breaches, AI and More
Actively Exploited
A hacker is reportedly selling a massive database containing the personal information of 340 million OnlyFans users. This database appears to have been created by combining data from previous breaches and matching it with public profiles to identify real OnlyFans accounts. The implications are serious, as this kind of data leak can lead to identity theft, harassment, or other malicious activities targeting the users involved. OnlyFans users should be particularly cautious about their online security and consider changing their passwords and enabling two-factor authentication. This incident raises broader concerns about the security of online platforms and the risks associated with sharing personal information.
A significant security vulnerability has been identified in Ghost CMS, specifically a SQL injection flaw labeled CVE-2026-26980. Attackers are exploiting this weakness to inject harmful JavaScript code, which activates ClickFix attack flows across numerous websites utilizing this content management system. This exploitation poses a serious risk to users by potentially compromising their data and functionality of affected sites. Ghost CMS users, particularly those running outdated versions, should take immediate action to secure their systems. This incident highlights the ongoing need for vigilance in web security and the importance of keeping software up to date.
Recent reports indicate that the popular npm package 'node-ipc' has been compromised with a credential-stealing malware. This incident affects developers who rely on this package for their applications, potentially exposing sensitive user information. Additionally, a new group called TeamPCP has emerged, deploying clones of the Shai-Hulud malware, which may pose further risks to various systems. Moreover, active supply chain attacks have targeted '@antv' packages on npm, putting more developers at risk. The compromised GitHub Action 'actions-cool/issues-helper' has also been found to redirect all tags to malicious endpoints, heightening concerns over the security of widely-used development tools. Developers and organizations should take immediate precautions to secure their environments and monitor for any unusual activity.
Anthropic's AI initiative, Project Glasswing, has identified over 10,000 serious vulnerabilities within just one month of operation. This alarming discovery exposes a significant gap in the ability of organizations to patch and manage these vulnerabilities effectively. The vulnerabilities range in severity from high to critical, raising concerns for companies and users who rely on the affected systems. As the number of vulnerabilities continues to grow, it becomes increasingly clear that many organizations struggle with timely patching and security management. This situation not only jeopardizes the security of sensitive data but also highlights the urgent need for improved cybersecurity practices across the industry.
Last week, the hacking group TeamPCP claimed to have breached GitHub's internal codebase by using a poisoned Visual Studio Code (VS Code) extension. GitHub, owned by Microsoft, confirmed the breach and has since launched an investigation into how their private code repositories were compromised. This incident raises serious concerns about the security of development tools widely used by programmers. Moreover, researchers recently discovered a critical flaw in NGINX, a popular web server software, which is being actively exploited. These incidents highlight the ongoing vulnerabilities in essential software and the need for robust security measures to protect sensitive information.
A recent supply chain attack has compromised Laravel Lang localization packages, leading to the distribution of credential-stealing malware. Attackers exploited GitHub version tags to insert malicious code into Composer packages, which are widely used by developers for PHP applications. This incident puts numerous developers at risk, as the malicious packages can steal sensitive information such as login credentials. Those using affected Laravel Lang packages need to be vigilant and check their dependencies to ensure they are not using compromised versions. The attack raises concerns about the security of open-source software and the potential for similar incidents in the future.
Italian officials have taken action against the CINEMAGOAL app, a piracy tool that illegally provided access to popular streaming services like Netflix, Disney+, and Spotify. The app was reportedly using stolen authentication codes to bypass payment systems, allowing users to access content without subscriptions. This crackdown is significant as it not only protects the intellectual property rights of these streaming platforms but also highlights ongoing challenges in combating online piracy. By dismantling this network, authorities aim to deter similar activities in the future and safeguard legitimate services. The action is part of a broader effort to enforce copyright laws and ensure users are not misled into using illegal services.