Kodak confirms data breach claimed by ShinyHunters extortion gang

2026-06-17T07:23:29Z716d851601d15cfba541c0ac0eb2e9c23e1fb84cf67d6d46fae9cb86e1164bc7
AI API key theftBackdoor.TurnCISACVE-2026-54420DragonForceFortinet FortiSandboxGhostTreeJetBrains MarketplaceKodakNTFS junction evasionOpenID ConnectOptinMonsterRokarolla Android trojanShinyHuntersSimpleHelpSteam WorkshopWallpaper EngineWordPress plugin compromisebanking trojancritical vulnerabilitiesdata breachiRhythmmalicious pluginsransomwaresupply-chain attack

What happened

Multiple high-impact security developments reported: Kodak and iRhythm confirmed data breaches (ShinyHunters claimed the Kodak incident). CISA warned of an actively exploited LiteSpeed cPanel plugin flaw (CVE-2026-54420). Critical Fortinet FortiSandbox vulnerabilities are being actively exploited. A range of malware and abuse campaigns were observed — malicious JetBrains Marketplace plugins stealing AI API keys, the new Rokarolla Android banking trojan targeting 217 banking/crypto apps, Steam Workshop used to distribute malware via Wallpaper Engine packages, and Windows variants of SprySOCKS/T

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
716d851601d15cfba541c0ac0eb2e9c23e1fb84cf67d6d46fae9cb86e1164bc7
Enrichment time
2026-06-17T07:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.