United Natural Foods Inc. (UNFI), the primary distributor for Whole Foods hit with cyberattack beginning on June 5, 2025.

United Natural Foods Inc. (UNFI), the primary distributor for Whole Foods hit with cyberattack beginning on June 5, 2025.

United Natural Foods Inc. (UNFI), the primary distributor for Whole Foods and a major supplier to over 30,000 retailers across North America, experienced a significant cybersecurity incident beginning on June 5, 2025. The attack led to widespread disruptions in its operations, particularly affecting its ability to fulfill and distribute customer orders, including those to Whole Foods.
Bitsight’s Warning: 40,000 Security Cameras Exposed Globally

Bitsight’s Warning: 40,000 Security Cameras Exposed Globally

Bitsight, a cybersecurity ratings company, has issued a stark warning after its TRACE research team discovered over 40,000 internet-connected security cameras streaming live footage openly on the internet, with no passwords or meaningful security protections in place. These cameras, intended for use in homes, businesses, factories, hospitals, and even public transportation, are inadvertently providing public access to sensitive locations and information.
Microsoft’s June 2025 Patch Tuesday addressed a total of 66–67 vulnerabilities across its product suite, including Windows, Microsoft Office, and related components.

Microsoft’s June 2025 Patch Tuesday addressed a total of 66–67 vulnerabilities across its product suite, including Windows, Microsoft Office, and related components.

Microsoft’s June 2025 Patch Tuesday addressed a total of 66–67 vulnerabilities across its product suite, including Windows, Microsoft Office, and related components. The update is notable for patching a critical zero-day vulnerability in the Web Distributed Authoring and Versioning (WEBDAV) protocol that was actively exploited in the wild.
Interpol dismantles more than 20,000 malicious IP addresses and domains linked to 69 different information-stealing malware variants.

Interpol dismantles more than 20,000 malicious IP addresses and domains linked to 69 different information-stealing malware variants.

On Wednesday, INTERPOL announced the successful dismantling of more than 20,000 malicious IP addresses and domains linked to 69 different information-stealing malware variants. This operation, codenamed Operation Secure, was conducted between January and April 2025 and involved law enforcement agencies from 26 countries across the Asia-Pacific region.
FIN6 (aka Camouflage Tempest, Gold Franklin, or Skeleton Spider) have adopted a novel attack vector using AWS-hosted fake resumes on LinkedIn to deliver More_eggs malware.

FIN6 (aka Camouflage Tempest, Gold Franklin, or Skeleton Spider) have adopted a novel attack vector using AWS-hosted fake resumes on LinkedIn to deliver More_eggs malware.

FIN6 (aka Camouflage Tempest, Gold Franklin, or Skeleton Spider) is a financially motivated cybercrime group active since 2012, initially targeting point-of-sale systems to steal payment card data. Recently, they’ve adopted a novel attack vector using AWS-hosted fake resumes on LinkedIn to deliver More_eggs malware, specifically targeting corporate recruiters.
China hit with record-breaking data leak of over 4 billion records.

China hit with record-breaking data leak of over 4 billion records.

The database consisted of numerous collections, ranging from half a million to over 800 million records gathered from various sources. One research team believes the dataset was meticulously compiled and maintained to build comprehensive behavioral, economic, and social profiles of nearly any Chinese citizen. The exposed instance was quickly taken down, preventing the team from disclosing the identity of the database’s owners.
SNMP Hacking

SNMP Hacking

Simple Network Management Protocol (SNMP) was designed to monitor network devices. It also enables remote configuration and setting changes. SNMP Community strings provide information and statistics about routers and devices.
SMTP Hacking

SMTP Hacking

The Simple Mail Transfer Protocol (SMTP) is a protocol for sending emails in an IP network. It can be used between an email client and an outgoing mail server or between two SMTP servers. SMTP is often combined with the IMAP or POP3 protocols, which can fetch emails and send emails.
New Mirai malware variant targeting DVR video devices.

New Mirai malware variant targeting DVR video devices.

A new variant of the Mirai malware botnet is exploiting a little-known command injection vulnerability in TBK digital video recording devices, specifically models DVR-4104 and DVR-4216, to take control of them. This vulnerability, identified as CVE-2024-3721, was disclosed by security researcher "netsecfish" in April 2024 but has just now been spotted in the wild.
SMB Hacking

SMB Hacking

SMB (Server Message Block) is a widely used protocol on Windows systems that offers various paths for vertical and lateral movement within a network. Samba allows Linux and Unix distributions to utilize the SMB protocol.