BARR Advisory Senior Consultant Teddy VanGalen has picked out five security and compliance headlines from the past month that you need to know. Take a look to find out what our consulting team has been reading this June—plus, scroll to see Teddy’s CISO Pick of the Month for his top new resource for security and compliance professionals this month.
The U.S. government has ordered Anthropic to suspend foreign nationals’ access to its advanced Claude Fable 5 and Mythos 5 models due to national security concerns, prompting the company to abruptly disable them for all users. The export control directive was reportedly driven by fears of access by a Chinese-linked group and Amazon research showing the model could be prompted to aid cyberattacks. While the government cited a narrow “jailbreak” method that allows users to bypass safety guardrails, Anthropic argues the capability is widely available in other commercial models and is used daily by defenders to patch software flaws.
➡️ Read more
A threat actor that calls itself ShadowByte$ is demanding a $2 million ransom from Nintendo after allegedly stealing roughly 859MB of internal corporate data. While it remains unclear whether the gaming giant was breached directly or compromised through its third-party employee engagement software, TinyPulse, researchers note that the leaked samples appear authentic. The data reportedly spans a decade’s worth of historical records from 2016 through 2026, containing employee names, corporate email addresses, and internal sentiment surveys.
➡️ Read more
An unidentified researcher going by “Nightmare Eclipse” has released “RoguePlanet,” a new Microsoft Defender zero-day exploit that allows local privilege escalation. The vulnerability (CVE-2026-50656) abuses a race condition to grant authenticated attackers SYSTEM-level command execution on fully patched Windows 10 and 11 devices, bypassing signature-based mitigations regardless of whether Real-Time Protection is enabled. Microsoft has acknowledged the issue and rated it “Exploitation More Likely,” but since signature blocks are ineffective, teams will simply have to stay vigilant while the vendor works on a formal security patch.
➡️ Read more
In a rapid 88-minute automated publishing campaign, a hijacked account belonging to a former Mastra contributor was used to push out 144 malicious npm packages. While the framework’s packages don’t contain malicious code themselves, the supply chain attack inserts a third-party library dependency called “easy-day-js” to drop a stealthy, credential-stealing trojan. Because Mastra is a popular framework for building AI applications, these packages are routinely deployed in high-value cloud environments that handle highly sensitive credentials.
➡️ Read more
A recent analysis from The Hacker News reveals that a striking number of organizations are unnecessarily exposing critical internal systems to the public internet, with 60% leaving HTTP panels exposed and 42% leaving databases directly reachable. According to the data, MySQL and Postgres databases take the top two exposure slots, while overlooked assets like private API documentation and legacy internal services frequently turn into documented attack paths. While most security teams focus heavily on keeping up with rapid patching cadences, these widespread findings highlight that attack surface reduction is simply not getting the same attention as vulnerability management.
➡️ Read more
🗺️ Map Your Healthcare Compliance Journey 🧭
For healthcare organizations, safeguarding sensitive data isn’t just a technical responsibility—it’s a business imperative. Whether you’re establishing a compliance program with HIPAA and HITRUST or maturing your compliance posture with standards like SOC 2, ISO 27001, FedRAMP, or CMMC, BARR’s healthcare team has put together a comprehensive guide to help you navigate the compliance journey from start to finish.
It’s a must-read resource for organizations in the healthcare industry—from hospitals to insurers and medical device manufacturers to telehealth providers.
Download now ➡️
Want to get these insights straight to your inbox? Subscribe to Take5, our monthly newsletter featuring top security and compliance headlines, events, and resources—brought to you by CISOs from BARR’s cybersecurity consulting team.