Nintendo confirms data stolen in WebMD subsidiary cyberattack
2026-06-18T19:23:27Z•243ad514812e6f30e76dbc3001f4ef9419244d709c9070acf8196d6ae9422507
apple-beatsbeets-studio-budsbluetoothclipboard-stealercredential-leakcrypto-stealerdata-theftevil-corpf5fortibleedfortinetincident-responsenginxoauth-breachout-of-band-patchsalesforceshapedpluginsocgholishsupply-chaintelecom-blockingusb-wormwordpress
What happened
Multiple high-impact security events reported on 18 Jun 2026: a data-theft incident at TinyPulse (affecting Nintendo survey data) linked to a WebMD subsidiary breach; a self-spreading USB worm distributing clipboard‑stealer crypto malware over Windows shortcut (.lnk) files with Tor-based C2; an OAuth compromise at Klue used by the "Icarus" actors to exfiltrate Salesforce CRM data; a supply‑chain compromise of ShapedPlugin updates infecting WordPress sites; and a large FortiBleed leak exposing VPN credentials for ~73,932 Fortinet/FortiGate URLs. Separately, law enforcement removed ~15,000 SocGh
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 243ad514812e6f30e76dbc3001f4ef9419244d709c9070acf8196d6ae9422507
- Enrichment time
- 2026-06-18T19:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.