News Jun 28, 2026 👁 17

IT News Roundup: AI Infrastructure Spending, Critical Vulnerabilities, and Major Breaches - June 28, 2026

This week in IT news: Alphabet announces an 0 billion AI infrastructure plan, a critical FFmpeg vulnerability enables remote code execution via video files, Fortinet devices face a major compromise campaign, and ShinyHunters targets multiple high-profile victims.

The past week has been dominated by massive shifts in AI infrastructure investment, several critical security vulnerabilities making headlines, and a wave of data breaches targeting both government and corporate entities. From Alphabet's historic 0 billion spending plan to the FFmpeg PixelSmash vulnerability affecting video processing worldwide, IT professionals need to stay aware of these developments.

Alphabet Announces 0 Billion AI Infrastructure Investment Plan

In one of the largest technology infrastructure commitments in history, Alphabet has announced an 0 billion plan dedicated to expanding its artificial intelligence capabilities. The investment covers data center construction, custom chip development, and cloud computing expansion designed to support next-generation AI models.

The announcement signals intensifying competition among major tech companies for AI dominance. With training costs for frontier models continuing to rise exponentially, infrastructure capacity has become the primary bottleneck in AI development. This level of investment also raises questions about energy consumption, environmental impact, and market concentration in the AI sector.

Source: ImFounder

FFmpeg PixelSmash Vulnerability Enables Remote Code Execution via Video Files

A critical vulnerability dubbed PixelSmash has been discovered in FFmpeg, the widely-used open-source multimedia framework that powers video processing for countless applications including web browsers, media servers, and content management systems. The flaw allows attackers to execute arbitrary code remotely by crafting malicious video files.

The vulnerability is particularly concerning because FFmpeg is embedded in so many products across the software ecosystem. Any application that processes user-uploaded video content could potentially be exploited without additional patches at the application level. Security researchers recommend updating FFmpeg immediately and implementing strict input validation for any system handling untrusted media files.

Source: eSecurity Planet

Major Hack Campaign Targets Fortinet Devices, Compromising Prominent Organizations

Security researchers have uncovered a significant cyberattack campaign targeting Fortinet network security devices. The breach has compromised prominent organizations worldwide, with attackers exploiting vulnerabilities in the widely-deployed firewall and security appliance line to gain access to internal networks.

The campaign highlights ongoing risks associated with supply chain attacks on networking infrastructure. Organizations relying on Fortinet products are urged to review their device configurations, apply all available patches immediately, and monitor for signs of unauthorized access. The incident underscores the importance of defense-in-depth strategies even when using dedicated security hardware.

Source: Reuters Cybersecurity

ShinyHunters Extortion Gang Targets Eastman Kodak and Madison Square Garden

The ShinyHunters cybercrime group has continued its aggressive extortion campaign throughout June 2026, targeting multiple high-profile victims simultaneously. Eastman Kodak confirmed that an unauthorized third party briefly accessed a limited amount of company data after the group listed the company on its leak site and threatened to publish over 2.2 million records containing customer personally identifiable information.

In a separate operation, ShinyHunters released a 45 GB archive of data tied to Madison Square Garden Sports after the company reportedly declined to pay a ransom demand. The release came just days after the New York Knicks captured the NBA Finals, adding public relations pressure to the security incident. The group has been running multiple parallel extortion tracks rather than working sequentially, making coordinated defense more challenging.

Source: SWK Technologies

Texas State Government Breach Exposes 3 Million Driver's Licenses and Passport Numbers

A data breach at a Texas state government department has exposed the driver's license information and passport numbers of more than 3 million people, according to the state attorney general. The incident ranks among the largest data breaches to affect the state this year.

The exposure of passport numbers is particularly alarming, as these documents are critical for international travel and identity verification. Affected individuals face elevated risks of identity theft and fraud. State officials have been working to notify impacted residents and provide credit monitoring services, though the full scope of the breach continues to be assessed.

Source: Cyber Security Review

Akrites Framework Launched for Critical Open Source Project Security

A new security framework called Akrites has been introduced to help critical open-source projects manage vulnerability response more effectively. The framework was developed in response to the accelerating pace at which AI-powered tools can discover and exploit software flaws, dramatically shortening the window between vulnerability disclosure and active exploitation.

The Akrites framework provides structured guidance for triage, patching priorities, and coordinated disclosure processes tailored specifically for projects that form critical infrastructure. As open-source components continue to underpin an estimated 87% of codebases at risk from vulnerabilities, standardized security response frameworks become increasingly essential for maintaining software supply chain integrity.

Source: Help Net Security

AI-Driven Vulnerability Discovery Pushes 2026 CVE Count Toward 66,000

The number of Common Vulnerabilities and Exposures (CVEs) disclosed in 2026 is on track to approach 66,000 — a significant increase driven largely by AI-powered bug hunting tools. While the total volume of reported vulnerabilities continues climbing, the proportion requiring urgent patches has remained relatively flat.

This trend reflects both the democratization of vulnerability research through AI assistance and improved automated scanning capabilities. For IT teams managing patching operations, the sheer volume means prioritization frameworks like EPSS (Exploit Prediction Scoring System) are more important than ever for focusing remediation efforts on the vulnerabilities most likely to be exploited in the wild.

Source: Help Net Security


← Back to Blog