daily cyber × ai intelligence

index

tagged

[novo-nordisk]

5 editions · 4 items

September 12, 2026

  • FulcrumSec says exposed GitHub tokens opened Novo Nordisk’s environment. DataBreachToday reports that the extortion group claims credentials embedded in client-side JavaScript provided initial access. It later released more than 1 TB of stolen data after the Danish company refused payment. The access narrative remains an operator claim rather than independently verified forensics. · Cloud & Identity

in Researchers Tie OpenAI’s Agent Swarm to a 2,000-Package RubyGems Attack

June 20, 2026

FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token

FortiBleed has compromised ~86,644 internet-facing FortiGate devices in a credential-harvesting campaign, while a leaked GitHub token gave FulcrumSec access to Novo Nordisk, exfiltrating 1.3TB including unreleased drug formulas and internal AI models. Mastra npm packages were trojanized by Sapphire Sleet (North Korea–nexus), and multiple AI infrastructure flaws emerged: SearchLeak (CVE-2026-42824) in Microsoft 365 Copilot, Pickle in the Middle in Google Vertex AI, and vulnerabilities in LiteLLM. Ransomware gangs including Qilin, Gentlemen, and DragonForce continue dominating the threat landscape with EDR-killing tradecraft and cloud-based C2 abuse.

June 19, 2026

  • Novo Nordisk was breached after FulcrumSec found a GitHub token left in a repo for two months, ultimately exfiltrating 1.3TB including unreleased drug formulas and internal AI models; the company refused a $25M extortion demand and the data is now being sold (Dark Reading, SecurityWeek). A clean reminder that secrets management is an identity problem, not a tooling one. · Threat Activity & Intrusions

in FortiBleed Burns 70,000+ Fortinet Edge Devices While a Leaked GitHub Token Guts Novo Nordisk

June 18, 2026

  • Novo Nordisk (Danish pharma giant) confirmed a breach in which FulcrumSec claims 1.3TB exfiltrated and a $25M ransom — notably including the company's internal AI assets: a 16GB trained model checkpoint, proprietary training data, full pipeline source (modeling_novopert.py), 113 training-run logs, and HPC/Slurm/SSH infrastructure maps. A concrete example of AI model/IP theft as an extortion payload (SecurityWeek, vx-underground). · Data Breaches (Nordic emphasis)

in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel

June 17, 2026

  • Novo Nordisk (Danish, maker of Ozempic) confirmed an IT breach; the threat actor claims to have stolen a 16GB trained model checkpoint, a proprietary training dataset, full source code and training pipeline, 113 training-run logs, and internal HPC/Slurm/SSH infrastructure maps. A notable example of an internal AI program becoming the crown-jewel target. SecurityWeek, vx-underground. · AI & Model Security

in Microsoft 365 Copilot 'SearchLeak' Enables One-Click Data Theft as Novo Nordisk Loses Internal AI Models to Extortionists