Several organizations across the financial, defense, and manufacturing sectors have recently disclosed ransomware attacks or data breaches. These incidents include a US financial institution, a Spanish defense contractor, a Japanese industrial manufacturer, and a US insurance firm's Japanese operations.
River Bank & Trust, a US financial institution, experienced a ransomware incident after an unauthorized actor accessed the network of its parent company, River Financial Corporation, on June 16. The bank confirmed the presence of ransomware on parts of its server environment and is currently evaluating whether personal data was accessed or exfiltrated.
Indra Group, a Spanish defense, aerospace, and technology contractor and a member of the NATO cyber coalition, confirmed a ransomware attack that impacted one of its subsidiaries. The Gentlemen ransomware gang claimed responsibility and threatened to leak allegedly stolen data. Indra Group, however, stated that the incident was contained and that service continuity was maintained.
Nidec, a Japanese electric motor and industrial manufacturer, disclosed a ransomware attack affecting the network of its Taiwanese subsidiary, Nidec Chaun Choung Technology. The BlackField group claimed responsibility for this attack, alleging the theft of over two terabytes of corporate data. This allegedly stolen data includes employee, financial, procurement, manufacturing, legal, and IT records.
Separately, US insurance firm Aflac disclosed a data breach affecting its Japan operations. Attackers accessed its policyholder portal between June 15 and June 25, exposing personal and financial data for nearly 4.4 million customers. The compromised information included policyholder details and premium payment account information.
In other cybersecurity news, researchers have identified new attack techniques and vulnerabilities. A browser-native ransomware technique, generated by a large language model, has been demonstrated to abuse Chrome's File System Access API. This method uses a fake image-enhancement page to trick users into granting folder access, subsequently reading, exfiltrating, and encrypting photos within the browser on Android and Windows devices.
Furthermore, shell command injection weaknesses were found in open-source AI coding agents, with 10 out of 11 popular tools failing to block obfuscated destructive commands. Simple rewrites allowed attackers to bypass filters and perform actions like file deletion. Only the Continue agent was noted to properly parse commands. Researchers also warned about attackers exploiting LLM phantom squatting by registering AI-generated domains to hijack traffic and deliver phishing attacks, recording 250,000 hallucinated domains and subsequent registrations, including an AI-built phishing kit named Montana Empire.
Several critical vulnerabilities have also been addressed. Oracle E-Business Suite is affected by CVE-2026-46817, a critical remote code execution flaw reportedly exploited against approximately 950 internet-exposed instances globally, which could grant attackers control over ERP systems. Linux kernel maintainers patched CVE-2026-46242, a "Bad Epoll" privilege escalation flaw affecting Linux servers, desktops, and Android devices. This race-condition use-after-free vulnerability allows unprivileged local users to gain root access, with a public exploit demonstrating reliable exploitation.
Citrix addressed CVE-2026-8451, a NetScaler ADC and NetScaler Gateway memory disclosure flaw impacting SAML Identity Provider configurations, with active exploitation observed less than 24 hours after disclosure, enabling attacks to leak session tokens. Progress also addressed CVE-2026-8037, a critical OS command injection flaw in Kemp LoadMaster load balancers with a CVSS score of 9.6. Exploitation attempts for this vulnerability began on June 29, potentially allowing unauthenticated remote code execution.
Threat intelligence reports highlighted a North Korea-aligned supply-chain campaign, PolinRider, which published 108 malicious packages and a Chrome extension across open-source registries, abusing VS Code auto-run tasks and hidden JavaScript loaders to deploy DEV#POPPER and OmniStealer. A partnership between the Vect ransomware group and TeamPCP, a supply chain credential-theft gang, was observed, industrializing ransomware delivery, with at least one Vect attack confirmed using TeamPCP-sourced credentials. The ChocoPoC campaign was also detected, weaponizing fake proof-of-concept exploits on GitHub and PyPI to infect vulnerability researchers with a Python RAT that steals files and browser data. Lastly, analysis of 3,000 live ClickFix payloads revealed rotating wrappers, custom command generation, and a Downloads-folder technique designed to bypass AMSI protections, indicating its evolution into an API-driven malware delivery ecosystem.






