AIO APEX

News

Breaking news and updates from the world of technology.

144 Mastra npm Packages Backdoored in 88-Minute Supply Chain Attack
Security

144 Mastra npm Packages Backdoored in 88-Minute Supply Chain Attack

An attacker hijacked a contributor account with publishing rights to the Mastra AI framework's npm organization and republished 144 packages with a typosquatted dependency that deployed a cross-platform infostealer. Any system that ran npm install with a @mastra/* package after June 16 is potentially compromised.

Socket
supply-chain-attackmalware
15 malicious JetBrains plugins spent 8 months stealing developers' AI API keys
Security

15 malicious JetBrains plugins spent 8 months stealing developers' AI API keys

Attackers published 15 fake AI coding plugins on the JetBrains Marketplace under seven vendor accounts, collectively downloaded nearly 70,000 times. Each plugin silently exfiltrated OpenAI, DeepSeek, and SiliconFlow API keys to an attacker-controlled server.

BleepingComputer
api-keyssupply-chain-attack
Google Sued a Chinese Cybercrime Ring for Using Gemini to Write Its Phishing Pages
Security

Google Sued a Chinese Cybercrime Ring for Using Gemini to Write Its Phishing Pages

Google filed suit in New York on June 12 against Outsider Enterprise, a China-based phishing-as-a-service operation that used Gemini to generate convincing fraud pages impersonating Google, USPS, E-ZPass, and banks. The FBI estimates the group stole 3.87 million credit card numbers and caused $1.9 billion in losses since July 2023. It is the first lawsuit Google has brought against threat actors for weaponizing its own AI.

The Next Web
Googlegemini
ShinyHunters Exploited CVE-2026-35273 for Two Weeks Before Oracle Issued a Patch, Breaching 100+ Organizations
Security

ShinyHunters Exploited CVE-2026-35273 for Two Weeks Before Oracle Issued a Patch, Breaching 100+ Organizations

The ShinyHunters group exploited a critical Oracle PeopleSoft zero-day for a full two weeks before Oracle published any patch, compromising more than 100 organizations and over 300 PeopleSoft instances worldwide. Universities bore the brunt of the attack, with the University of Nottingham among the confirmed victims and data on 455,000 individuals now circulating in leaked datasets.

The Hacker News
zero-daydata-breach
Microsoft's June Patch Tuesday Fixes 200 Flaws — a Record, and Likely the New Normal
Security

Microsoft's June Patch Tuesday Fixes 200 Flaws — a Record, and Likely the New Normal

Microsoft's June 2026 Patch Tuesday is the largest in the company's monthly update history: 200 vulnerabilities patched, 38 rated critical, and six zero-days — three with exploit code already public. Researchers say AI-assisted bug hunting is why, and that this volume may not be a one-time event.

Krebs on Security
Microsoftwindows