Kodak confirms data breach claimed by ShinyHunters extortion gang
2026-06-17T07:23:29Z•716d851601d15cfba541c0ac0eb2e9c23e1fb84cf67d6d46fae9cb86e1164bc7
AI API key theftBackdoor.TurnCISACVE-2026-54420DragonForceFortinet FortiSandboxGhostTreeJetBrains MarketplaceKodakNTFS junction evasionOpenID ConnectOptinMonsterRokarolla Android trojanShinyHuntersSimpleHelpSteam WorkshopWallpaper EngineWordPress plugin compromisebanking trojancritical vulnerabilitiesdata breachiRhythmmalicious pluginsransomwaresupply-chain attack
What happened
Multiple high-impact security developments reported: Kodak and iRhythm confirmed data breaches (ShinyHunters claimed the Kodak incident). CISA warned of an actively exploited LiteSpeed cPanel plugin flaw (CVE-2026-54420). Critical Fortinet FortiSandbox vulnerabilities are being actively exploited. A range of malware and abuse campaigns were observed — malicious JetBrains Marketplace plugins stealing AI API keys, the new Rokarolla Android banking trojan targeting 217 banking/crypto apps, Steam Workshop used to distribute malware via Wallpaper Engine packages, and Windows variants of SprySOCKS/T
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 716d851601d15cfba541c0ac0eb2e9c23e1fb84cf67d6d46fae9cb86e1164bc7
- Enrichment time
- 2026-06-17T07:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.