IT News Roundup: AI Funding Surge, npm Supply Chain Attacks, Oracle Vulnerabilities - June 30, 2026
This week in IT news: Alphabet raises $80 billion for AI infrastructure, multiple npm supply chain attacks target open-source frameworks, Oracle WebLogic flaw added to CISA KEV catalog, and ShinyHunters extortion campaign hits Kodak and MSG.
The technology landscape this week was dominated by massive capital commitments to artificial intelligence, a wave of software supply chain attacks targeting the npm ecosystem, critical enterprise vulnerabilities reaching federal enforcement deadlines, and an aggressive round of data extortion from one of the most active cybercrime groups operating today.
Alphabet Raises $80 Billion for AI Infrastructure Buildout
Google parent company Alphabet announced plans to raise up to $80 billion through stock sales to fund a massive expansion of its artificial intelligence infrastructure. The capital raise includes a $10 billion commitment from Berkshire Hathaway, Warren Buffett's investment vehicle, signaling strong institutional confidence in the long-term trajectory of AI compute demand.
Alphabet stated that demand for its AI services is growing faster than available supply, and the new funding will be directed toward building additional data centers, deploying next-generation chips, and expanding global computing capacity. The announcement caused Alphabet's stock to slide approximately 2.7% in premarket trading on June 1, as investors weighed the dilution impact against the scale of planned investment.
The move underscores how AI infrastructure has become a central strategic battleground among Big Tech companies, with capital deployment now measured in tens of billions rather than hundreds of millions. For IT professionals and homelab enthusiasts tracking industry trends, this signals continued growth in demand for cloud compute resources and the underlying hardware that powers them.
Source: CNBC, TechCrunch
Massive npm Supply Chain Attacks: Mastra, Red Hat Packages Compromised
The npm package ecosystem faced a series of significant supply chain attacks throughout June 2026. Researchers from Endor Labs, JFrog, OX Security, SafeDep, Socket, StepSecurity, and Snyk identified that as many as 145 packages under the @mastra/* namespace โ part of a popular open-source JavaScript/TypeScript framework for building AI applications โ were compromised in an attack codenamed easy-day-js. A single hijacked npm account was used to push malicious versions across the affected packages.
In a separate campaign, JFrog Security Research analyzed 31 hijacked versions of @redhat-cloud-services npm packages carrying a new Shai-Hulud worm variant dubbed "Miasma: The Spreading Blight." The attack uses install-time execution, layered JavaScript obfuscation, Bun-based payload delivery, credential theft, and self-propagation through GitHub and npm. The campaign also deployed destructive persistence mechanisms on compromised systems.
Additionally, JFrog identified two other hijacked packages (html-to-gutenberg and fetch-pacage-assets) that used hidden VS Code tasks to launch a multi-stage malware chain targeting credentials, browsers, cryptocurrency wallets, and developer tools. The attackers deliberately avoided common npm lifecycle scripts in an apparent attempt to remain compatible with npm v12's security hardening measures.
Sources: The Hacker News, JFrog Security Research
CISA Adds Oracle WebLogic Vulnerability to KEV Catalog After Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2024-21182, a high-severity vulnerability in Oracle WebLogic Server, to its Known Exploited Vulnerabilities (KEV) Catalog on June 1, 2026. The flaw carries a CVSS score of 7.5 and allows an unauthenticated attacker with network access to take full control of affected servers.
The vulnerability had been patched by Oracle two years prior, but CISA's listing was triggered by confirmed evidence of active exploitation in the wild. Under Binding Operational Directive (BOD) 22-01, all U.S. federal agencies were mandated to remediate the vulnerability by June 23, 2026. The KEV Catalog serves as a living list of vulnerabilities that are known to be actively exploited and represents one of the most actionable threat intelligence resources available to security teams.
This case highlights the persistent risk of unpatched legacy systems in enterprise environments. Organizations running Oracle WebLogic Server should verify their patch levels immediately, even if they believe they applied updates previously โ supply chain compromises and misconfigured update processes can leave systems exposed despite official remediation efforts.
Sources: CISA, The Hacker News
Oracle June 2026 Critical Patch Update Addresses Dozens of Severity Flaws
Oracle released its June 2026 Critical Patch Update (CSPU), one of the most significant patch releases of the year. The update addresses 122 critical vulnerabilities across Oracle's enterprise product portfolio, including four flaws rated at the maximum CVSS score of 10.0.
The affected products span a wide range of infrastructure and application software: Fusion Middleware, WebLogic Server, Coherence, E-Business Suite, JD Edwards, PeopleSoft, MySQL, Solaris, Siebel CRM, and VirtualBox. The breadth of the update means that IT teams managing Oracle-based environments face a substantial remediation workload.
The June CSPU is particularly notable for the number of remotely exploitable vulnerabilities with no authentication required โ a pattern that makes these flaws attractive targets for automated attack tooling. Organizations are advised to prioritize patching WebLogic, MySQL, and Fusion Middleware components first, given their exposure on network-facing infrastructure.
Source: Intertec Systems
ShinyHunters Extortion Campaign Hits Kodak and Madison Square Garden
The cybercrime group ShinyHunters, one of the most prolific data extortion gangs currently active, continued an aggressive campaign throughout June 2026. Eastman Kodak confirmed a data breach after ShinyHunters listed the company on its dark web leak site on June 15 and threatened to publish over 2.2 million records of customer personally identifiable information and internal corporate files by a June 18 deadline.
Kodak stated that an unauthorized third party briefly accessed a limited amount of company data, but the full scope of the breach remains under investigation. The claimed dataset reportedly includes employee names, email addresses, analytics records, bank statement PDFs, and W-9 tax forms spanning from 2016 through early 2026.
In a parallel operation, ShinyHunters published a 45 GB archive of data tied to Madison Square Garden Sports after the company reportedly declined to pay a ransom. The release dropped just days after the New York Knicks captured the NBA Finals, amplifying the reputational damage. The group's strategy of running multiple parallel extortion tracks rather than sequential campaigns has made it one of the most disruptive threat actors operating in 2026.
Sources: Malwarebytes, CyberNews
OpenSSF Highlights Rising Stakes for Open Source Security in June Newsletter
The Open Source Security Foundation (OpenSSF) published its June 2026 newsletter, highlighting the escalating threats facing open source software supply chains. The European Open Source Security Forum focused on translating commitments from the Cyber Resilience Act (CRA) into actionable security practices for maintainers and distributors.
The Mini Shai-Hulud and Miasma worm campaigns targeting npm packages underscored the critical need for strong software provenance mechanisms, including signed releases and verifiable build pipelines. Despite these challenges, the open source security community made progress on several fronts, including improved vulnerability disclosure processes and expanded adoption of Software Bills of Materials (SBOMs).
The U.S. government's Open-Source Software Security Initiative continues to push for secure-by-design practices and memory-safe languages across federally funded software development. For homelabbers and self-hosted infrastructure operators, the message is clear: auditing dependencies, enabling automated vulnerability scanning, and keeping package managers updated are no longer optional best practices โ they are essential operational requirements.
Source: OpenSSF
โ Back to Blog