View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Medtronic data breach impacts 3.8 million people

🚨 ACTIVE EXPLOITS & INCIDENTS

  • PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords β€” The Hacker News A new macOS info stealer dubbed PamStealer, discovered by Jamf Threat Labs, is distributed as a malicious AppleScript impersonating the open-source clipboard manager Maccy. It exploits PAM (Pluggable Authentication Module) checks to harvest Mac login credentials, representing a novel macOS credential theft vector.
  • Medtronic Data Breach Impacts 3.8 Million People β€” SecurityWeek Medtronic confirmed a data breach from April 2026 involving the ShinyHunters extortion group, exposing personal and medical data of over 3.8 million individuals. The breach affects corporate IT systems and may have downstream risks for patient privacy and medical device security.
  • Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices β€” SecurityWeek Law enforcement and Google dismantled NetNut, a large-scale residential proxy service leveraging millions of compromised devices worldwide. This takedown disrupts a key infrastructure used by cybercriminals and nation-state actors to anonymize attacks and evade detection.

πŸ•΅οΈ THREAT RESEARCH & DEEP DIVES

  • Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign β€” Securelist (Kaspersky) Armored Likho APT is actively targeting organizations in Russia, Kazakhstan, and Brazil using spear-phishing and AI-generated loaders. Their new Python-based BusySnake Stealer tool exfiltrates sensitive data, marking an evolution in their malware capabilities and operational sophistication.

πŸ”“ VULNERABILITIES & CVEs

  • Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution β€” SecurityWeek The Cursor AI code editor suffers from β€œDuneSlide” vulnerabilities enabling zero-click prompt injection attacks that escape sandboxing and execute arbitrary OS-level code. These flaws pose a critical risk for developers using Cursor, potentially allowing remote compromise without user interaction. No CVE IDs published yet; immediate mitigation advised.

🚨 ACTIVE EXPLOITS & INCIDENTS

  • Alleged Scattered Spider Hacker Extradited to US β€” SecurityWeek Peter Stokes, 19, allegedly linked to Scattered Spider, a prolific ransomware and extortion group responsible for 100+ network intrusions and over $100M in ransom payments, has been extradited to the US. This marks a significant law enforcement milestone against a major ransomware affiliate network.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check