June Patch Tuesday digs into 67 bugs
An extremely Windows-heavy month, with a surprise cameo by… Sophos?!
The reconnaissance activity targeting American cybersecurity company SentinelOne was part of a broader set of partially-related intrusions into several targets between July 2024 and March 2025. “The victimology includes a South Asian government entity, a European media organization, and more than 70 organizations across a wide range of sectors,” security researchers Aleksandar Milenkoski and Tom
Lorenzo Franceschi-Bicchierai reports: More than a decade ago, researchers at antivirus company Kaspersky identified suspicious internet traffic of what they thought was a known government-backed group, based on similar targeting and its phishing techniques. Soon, the researchers realized they had found a much more advanced hacking operation that was targeting the Cuban government, among others….
Christopher Brown reports: PowerSchool Holdings Inc. is facing three federal lawsuits alleging the education software provider negligently failed to protect the personal information of students, parents, and teachers that was exposed in a December data breach. Sheilah Buack-Shelton, Tyler Baker, and Kimberly Kinney alleged in separate complaints that PowerSchool breached its duties under common law,…
There’s an update to a previously reported breach claimed by “Nullbulge.” Pirates and Princesses reports: A California resident has pleaded guilty to charges related to hacking a Disney employee’s personal computer, resulting in the theft of more than 1 terabyte of confidential data. Last year, it was reported that a hacker accessed Disney’s files and released…
Matt Wilson reports: The city of Mission expects the fallout from a debilitating ransomware attack last month to have an impact for months. The city said so in correspondence last Thursday seeking an attorney general’s opinion allowing it to withhold contracts with outside cybersecurity experts and legal council asked for by the Progress Times through…
Matthew Gault reports: Researchers published a massive database of more than 2 billion Discord messages that they say they scraped using Discord’s public API. The data was pulled from 3,167 servers and covers posts made between 2015 and 2024, the entire time Discord has been active. Though the researchers claim they’ve anonymized the data, it’s…