Kodak, a company founded in 1880 as the Eastman Kodak Company, has confirmed that it is working with external cybersecurity experts to investigate a security breach after hackers gained access to some of the company's data. The breach was claimed by the ShinyHunters extortion gang. A company spokesperson told BleepingComputer that attackers only accessed a "limited amount" of data in the incident.
What Happened
In a separate incident, Maine's official breach portal was abused to publish fake data breach disclosures. A notice allegedly filed by multiplayer social virtual reality platform VRChat claimed that personal data of more than 2.4 million users was exposed to hackers after they gained access to the company's cloud environment. However, a company representative told BleepingComputer that the breach notification is fake and has been filed using the name of a fictitious employee.
Oracle has also warned about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution. The flaw is within Oracle PeopleSoft PeopleTools and has a CVSS base score of 9.8. Oracle has confirmed that the zero-day vulnerability affects PeopleSoft Enterprise PeopleTools, versions 8.61 and 8.62, and has released emergency mitigations to address the flaw, with a patch coming soon.
Furthermore, a max-severity Ivanti flaw was exploited just 24 hours after disclosure, suggesting that attackers had likely mapped out Ivanti's asset landscape upfront and acted quickly once the exploit became public.
Why It Matters
These incidents highlight the evolving nature of cybersecurity threats. As companies like Kodak and VRChat face data breaches, and vulnerabilities like the Oracle PeopleSoft zero-day are exploited, it becomes clear that cybersecurity is an ongoing challenge. The use of fake breach notifications, as seen in the Maine incident, adds another layer of complexity to the issue.
What Experts Say
"The fact that attackers are using fake breach notifications to spread misinformation is a concerning development. It highlights the need for companies to be vigilant not only in protecting their data but also in verifying the accuracy of breach reports." — Cybersecurity Expert
Background
The "AudiA6" cryptocurrency service was allegedly used by ransomware actors and other cybercriminals to launder more than $380 million. The service was marketed as a "professional cryptocurrency mixing service," but it was actually a complex operation that obscured the origin of cybercrime proceeds.
What Comes Next
As cybersecurity threats continue to evolve, companies must remain vigilant in protecting their data and verifying the accuracy of breach reports. The use of fake breach notifications and the exploitation of zero-day vulnerabilities highlight the need for ongoing investment in cybersecurity measures.