This Week in Cybersecurity
Each week at Applied Tech we recap the biggest cybersecurity news headlines from the week to keep you informed and ready to face the latest threats. Here’s your breakdown for the week of June 27th – July 4th!
Hackers Had Months-Long Access to Kubota Network
Between March and April of this year, threat actors accessed files with personal info for employees of Kubota North America and their dependents. The Japanese industrial manufacturer confirmed names, SSNs, DOBs, Taxpayer IDs, direct deposit information and more were exposed.
Kubota says it has implemented additional security measures, and recommends victims to monitor healthcare-related statements and bank accounts.
Source: BleepingComputer
Read More
Teenager Extradited to Face U.S. Hacking Charges
Peter Stokes, 19, a dual citizen of the US and Estonia, was arrested in Finland and extradited to the U.S. this past week. Stokes is charged with conspiracy, computer intrusion, and fraud as a member of the group Scattered Spider.
Stokes, who operated under the handle “Bouquet” has been active since he was 16. In one case, prosecutors allege he and others broke into a luxury retailer, copied data, and demanded about $8 million in cryptocurrency.
Source: U.S. Department of Justice
Read More
FCC Announces Bans on Chinese Equipment Linked to Cyber Risks
The United States Federal Communications Commission (FCC) announced a large ban on the import and sale of certain Chinese-made telecom equipment linked to both cybersecurity risks and potential spying.
The ban targets devices from companies like Huawei, ZTE, Hikvision, and others.
Source: Cybersecurity News
Read More
One of the Largest Password Stealing Attempts in History Targeted M365 Users with 81 Million Login Attempts
Huntress is tracking a major password-spray campaign that hit Microsoft 365 and Azure CLI between June 12-26, 2026, generating 81 million login attempts and compromising at least 78 accounts across 64 organizations. Attackers are replaying old, unrotated breached credentials through Azure CLI’s legacy ROPC authentication flow, which bypasses MFA because it skips the step where Conditional Access Policies normally enforce it.
Much of the traffic ties back to a provider called LSHIY LLC, with infrastructure and corporate links suggesting Chinese origin. Most affected organizations had MFA in place but with configuration gaps, such as scoping it to certain apps or groups, or leaving policies in report-only mode. Huntress recommends enforcing MFA across all users and apps, disabling legacy protocols like ROPC, and regularly testing Conditional Access configurations.
Source: Cybersecurity News
Read More

About Applied Tech, An HBS Brand
Applied Tech is a leading IT and cybersecurity services provider dedicated to helping organizations protect their digital assets and scale their IT capabilities. Our proactive services span cloud management, security, productivity, and IT growth strategy—delivered by an experienced team with solutions built around your goals.
As part of Heartland Business Systems, we now bring greater resources, broader capabilities, and deeper technical expertise to every client relationship.
Get in Touch with Us


