August 24, 2026
- ShinyHunters named BOK Financial and CyrusOne, with the CyrusOne listing citing a rejected $13M demand and claiming 12.9 million Salesforce records plus 645 GB of uncompressed SharePoint data, 182,000+ customer rows and 8,300+ rows of employee PII (@DarkWebInformer). The group also claims to have breached security firm ReliaQuest but has published no proof (campuscodi).
· Threat Activity & Cybercrime
in Four Days Dark: Iran-Linked Intrusion Knocked a UK Power Plant Offline
August 13, 2026
- The "City-Forum" campaign is quietly exfiltrating data from Salesforce and ServiceNow by abusing unauthenticated guest access to enumerate and pull exposed records. Active since at least March 2025 across multiple sectors, it uses custom tooling, per Dark Reading and SecurityWeek.
· Threat Activity
in ShieldBreak Turns a "Patched" Defender Bug Back Into SYSTEM
August 8, 2026
- ShinyHunters is advertising 11.5M records from an unnamed victim spanning Salesforce, ServiceNow, and Entra, plus 3.1 TB+ of internal corporate data. @DarkWebInformer
· Data Breaches
in OpenAI Pauses Its Astra Model After It Hits the "Critical" Cyber Threshold
August 2, 2026
- ShinyHunters resurfaces with new infrastructure and fresh victim claims. After announcing a "we're back" statement with new Telegram/X channels and a PGP key, the group has listed several new victims including Questel SAS (claiming 21M Salesforce records / 147 GB) and Lumenis (@DailyDarkWeb).
· Threat Intelligence
in Coldcard Wallet Theft Climbs Past $88M as Attackers Drain Weak-Entropy Addresses in Waves
July 15, 2026
- Microsoft mapped a year of ShinyHunters activity against Salesforce, finding attackers walked into corporate tenants without exploiting a single platform flaw — abusing existing OAuth trust between Salesforce and connected apps/third-party vendors, plus vishing and misconfigurations. Defender monitoring was updated in response. The Hacker News, Microsoft
· Cloud & Identity
in Record-Breaking Patch Tuesday Ships With Live Active Directory and SharePoint Zero-Days
June 22, 2026
A usbliter8 BootROM exploit for Apple A12/A13 devices and the LACUNA Chain EDR evasion technique represent major offensive advances, while Klue's OAuth token-theft incident exposed Salesforce customers to the Icarus actor. Supply-chain threats include a malicious node-fetch-utils npm package deploying fileless Python implants and active exploitation of CVE-2026-4020 in Gravity SMTP WordPress plugin.
June 21, 2026
- Klue, a competitive-intelligence platform, confirmed attackers stole OAuth tokens used to connect to customers' Salesforce environments, and the new Icarus extortion group has claimed it (BleepingComputer). Salesforce disabled the Klue Battlecards integration on June 11; this is the third Salesforce-connected app abused for CRM data theft, and confirmed victims include security vendors Huntress and Recorded Future (SecurityWeek, The Hacker News).
· Cloud & Identity
in FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog
June 20, 2026
FortiBleed has compromised ~86,644 internet-facing FortiGate devices in a credential-harvesting campaign, while a leaked GitHub token gave FulcrumSec access to Novo Nordisk, exfiltrating 1.3TB including unreleased drug formulas and internal AI models. Mastra npm packages were trojanized by Sapphire Sleet (North Korea–nexus), and multiple AI infrastructure flaws emerged: SearchLeak (CVE-2026-42824) in Microsoft 365 Copilot, Pickle in the Middle in Google Vertex AI, and vulnerabilities in LiteLLM. Ransomware gangs including Qilin, Gentlemen, and DragonForce continue dominating the threat landscape with EDR-killing tradecraft and cloud-based C2 abuse.
June 19, 2026
FortiBleed exposed working SSL-VPN credentials for 70,000+ Fortinet devices across 194 countries via industrialized hash-cracking by a Russian-speaking group, while a forgotten GitHub token cost Novo Nordisk 1.3TB of drug formulas and internal AI models. Critical vulnerabilities in NGINX (CVE-2026-42530), Cisco SD-WAN and ISE, Splunk, and Joomla are under active exploitation, alongside AI pipeline supply-chain attacks hitting Mastra, JetBrains Marketplace, and Google Vertex AI. The AtomicArch campaign compromised ~1,500 Arch Linux AUR packages with Rust infostealers and eBPF rootkits.