September 14, 2026
- Stolen police credentials opened Florida’s DAVID driver database. Florida says attackers used credentials taken from an officer’s personal device, The Record reports. BleepingComputer identifies the compromised account as belonging to a police-department employee with access to the FLHSMV system. ShinyHunters claims more than 2.8 million driver records, but the state’s confirmation establishes the access route, not necessarily the group’s full claimed scope.
· Identity & Data Exposure
in Hermes Logs Reveal Unattended AI Post-Exploitation
September 13, 2026
- Anthropic's 154-page report gains actor-level detail. The Russian state-sponsored cluster it calls GTG-20006 — sharing tradecraft with Midnight Blizzard/APT29 — built an AI-assisted workflow to rebuild malware after detection, in a campaign against more than 20 government, intelligence, diplomatic and defence organisations (The Hacker News, The Record). GTG-50014 (aka MeowSHA), a French-speaking suspected ShinyHunters affiliate, ran 10 AWS EC2 workers that pulled 1.8 million distinct Android APKs, scanned them with TruffleHog and pushed verified secrets to Telegram; a second ShinyHunters affiliate hit SaaS vendors to reach roughly 50 downstream organisations and maintained an autonomous vulnerability-research programme producing working exploits for unknown flaws in network and security appliances (The Hacker News, earlier coverage). Anthropic also describes users in Houthi-held Yemen attempting weapons development, including a failed guided-rocket test, without fielding an operational device (SecurityWeek). Worth reading the caveats: @cyb3rops notes the "sandbox escape" was internet access enabled by a misconfiguration, not a VM or container escape, and the "safety monitor" was another LLM reviewing transcripts after the fact.
· AI-Enabled Threat Activity
in Artifactory Chains Give Attackers Admin in Under Five Minutes
September 12, 2026
- Passkey and SSO-themed phishing is compromising corporate Microsoft 365 accounts. Microsoft links the campaigns to ShinyHunters, Helix, and other extortion crews seeking cloud data, BleepingComputer reports. The activity abuses passwordless-authentication branding through social engineering; it is not a cryptographic break in passkeys.
· Cloud & Identity
in Researchers Tie OpenAI’s Agent Swarm to a 2,000-Package RubyGems Attack
September 11, 2026
- Anthropic's September threat intelligence report documents a suspected Russian state-linked group using Claude across phishing, intrusion, data theft and malware development — including rebuilding malware after security products flagged it — against more than 20 organizations, plus ShinyHunters-linked actors running agents to scan 1.8 million Android apps. The framing is that AI is moving from advice into the operational loop: recon, exploitation, credential theft, persistence and victim-data triage (Anthropic). Practitioners are not uniformly sold: @keyth0s argues Anthropic's classifiers are "pretty bad for cyber dual use things" and easy to trip without real evidence (discussion).
· Offensive AI in the Wild
- AdaptHealth put the count at 4,115,802 individuals in its HHS filing. Entry was on 5 June through social engineering that compromised a third-party contractor's privileged account; a ransom demand followed on 15 June. ShinyHunters was named by HIPAA Journal, though the company's entry has since vanished from the group's portal (BleepingComputer).
· Breaches
in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign
September 8, 2026
- ShinyHunters claims a breach of the Florida DMV, using Jeffrey Epstein's driver's licence record as the public proof sample on its pay-or-leak site (vx-underground); Dark Web Informer suggests the licence data may have been bought from the Nexus market actor rather than stolen directly. In the Netherlands, police broadcast the Odido vishing suspect's voice on Opsporing Verzocht on 7 September: a Dutch-speaking man phoned customer service posing as an IT-department colleague and an employee unintentionally granted him access to an internal system, exposing data on more than six million customers. A voice expert concluded it is a real human voice, not AI-generated, and noted the caller's fluent English IT jargon suggests helpdesk experience (Dutch National Police). A ~100 GB Odido dataset is now being distributed publicly rather than sold (Daily Dark Web).
· Threat Activity
- Mathspace says 1,079,819 students, staff and parents in Australia and New Zealand had data stolen after attackers exploited a vulnerability in its self-hosted Metabase install to gain administrator access without a login. Access began 10 August, the Australian reporting database was downloaded 27 August, and the theft was confirmed 3 September; no academic records, password hashes, tokens or SSO credentials were exposed (BleepingComputer) — the latest in the run of Metabase SQL injection zero-day intrusions linked to ShinyHunters.
· Breaches
in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited
September 4, 2026
- ShinyHunters started publishing data after its extortion deadlines lapsed, marking McKesson (321GB+ compressed), Neogen (313GB+, claimed 5M+ Salesforce records), Swedish medtech Elekta AB and Jack Henry & Associates for download (Daily Dark Web, Dark Web Informer). Separately, Qilin is extorting the US ATF (vx-underground), following ATF's own "major incident" confirmation (earlier coverage).
· Threat Activity
in Malware That Gaslights the AI Analyst
August 29, 2026
- ShinyHunters listed McKesson and Swedish radiotherapy vendor Elekta AB. McKesson has filed an 8-K confirming an incident discovered on 25 August, with the investigation still early and materiality undetermined (BleepingComputer); the Elekta listing carries a 1 September deadline with no stated data volume (Dark Web Informer).
· Threat Activity
in PaperCut Ships a Second Emergency Patch After Researchers Bypass the First
August 27, 2026
in When the Sandbox Isn't a Boundary
August 25, 2026
- ReliaQuest confirms a ShinyHunters social-engineering attempt against one of its own employees, with the attacker impersonating a member of its security team; the company says the actor reached a dashboard but data theft failed (BleepingComputer, SecurityWeek).
· Threat Activity
in The Rogue Agent Staged an Apology, Then Pushed More Malware
August 24, 2026
- ShinyHunters named BOK Financial and CyrusOne, with the CyrusOne listing citing a rejected $13M demand and claiming 12.9 million Salesforce records plus 645 GB of uncompressed SharePoint data, 182,000+ customer rows and 8,300+ rows of employee PII (@DarkWebInformer). The group also claims to have breached security firm ReliaQuest but has published no proof (campuscodi).
· Threat Activity & Cybercrime
in Four Days Dark: Iran-Linked Intrusion Knocked a UK Power Plant Offline
August 16, 2026
- RingCentral breach data hits Have I Been Pwned — roughly 1.6M unique email addresses, plus names, physical addresses, and phone numbers, were dumped following the July social-engineering intrusion tied to ShinyHunters (earlier coverage). The Register
· Breaches
in Bring Your Own EDR: Turning a Commercial Endpoint Agent Into a Trojan Horse
August 15, 2026
in A Heavy Day for Exploit Research and In-the-Wild N-Days
August 13, 2026
in ShieldBreak Turns a "Patched" Defender Bug Back Into SYSTEM
August 12, 2026
- ShinyHunters is claiming a Metabase hacking spree, with leaked data now surfacing, following the still-uncredentialed unauthenticated SQL-injection zero-day Metabase patched last week (earlier coverage). Metabase urged customers to upgrade immediately (Metabase) (discussion).
· Threat Activity
in When the AI Is the One Finding the Zero-Days
August 9, 2026
- Exact Sciences (owned by Abbott) confirmed a ShinyHunters breach exposing 10.9 million records, including personal and health data, from a July 2026 incident — appearing to give a name to the extortion group's recently advertised multi-million-record haul (Have I Been Pwned) (earlier coverage).
· Threat Activity
in AI Agents' Black Hat Reckoning Goes Public
August 8, 2026
- ShinyHunters is advertising 11.5M records from an unnamed victim spanning Salesforce, ServiceNow, and Entra, plus 3.1 TB+ of internal corporate data. @DarkWebInformer
· Data Breaches
in OpenAI Pauses Its Astra Model After It Hits the "Critical" Cyber Threshold
August 2, 2026
- ShinyHunters resurfaces with new infrastructure and fresh victim claims. After announcing a "we're back" statement with new Telegram/X channels and a PGP key, the group has listed several new victims including Questel SAS (claiming 21M Salesforce records / 147 GB) and Lumenis (@DailyDarkWeb).
· Threat Intelligence
in Coldcard Wallet Theft Climbs Past $88M as Attackers Drain Weak-Entropy Addresses in Waves
August 1, 2026
- ShinyHunters claims a breach of residential security firm Brinks Home and is threatening to leak stolen data; the group separately announced a "we're back" return with new Telegram, X, and PGP channels (BleepingComputer, The Register).
· Threat Activity
in When the Attacker Is a Model: AI Lands on Both Sides of the Fight
July 28, 2026
- ShinyHunters claimed the Ernst & Young breach — saying it obtained credentials via a supply-chain attack — as the same group was tied to the DentaQuest breach potentially affecting over 15 million people (BleepingComputer, SecurityWeek).
· Threat Activity
in Agentic AI Muscles Into the Offensive Toolkit
July 27, 2026
- ShinyHunters leak data is fueling a $2,000 sextortion campaign. Scammers are mining email addresses from previously dumped datasets — attributed to Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill — to send targeted-looking Bitcoin demands; BleepingComputer confirmed some recipients appeared in the referenced dumps (BleepingComputer).
· Threat Activity
in Two Live Exploits and a Bench of Fresh Offensive Tooling
July 18, 2026
- Abbott investigating two incidents — confirmed unauthorized access to legacy Exact Sciences systems in its Cancer Diagnostics business (claimed by ShinyHunters) plus a separate claim of a breach of its LabCentral portal (BleepingComputer, Abbott statement).
· Breaches & Extortion
in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All
July 15, 2026
- Microsoft mapped a year of ShinyHunters activity against Salesforce, finding attackers walked into corporate tenants without exploiting a single platform flaw — abusing existing OAuth trust between Salesforce and connected apps/third-party vendors, plus vishing and misconfigurations. Defender monitoring was updated in response. The Hacker News, Microsoft
· Cloud & Identity
in Record-Breaking Patch Tuesday Ships With Live Active Directory and SharePoint Zero-Days
July 7, 2026
A 16-year-old KVM hypervisor vulnerability (CVE-2026-53359) enabling guest-to-host escape is under public exploitation, with panic PoCs already available. Adobe ColdFusion CVE-2026-48282 (CVSS 10.0) is being actively exploited in the wild within hours of disclosure, with unauthenticated remote code execution possible. AI-powered coding agents are now a live attack surface, with researchers demonstrating agent hijacking, malicious skill injection, and data exfiltration through prompt injection in creator tools like YouTube's Ask Studio. Iran-linked hackers are deploying a new modular C2 framework called Cavern against Israeli targets, while ClickFix malware operators are leveraging blockchain as a resilient command infrastructure.
July 6, 2026
- Medtronic is notifying nearly 3.8 million individuals after a ShinyHunters data theft exposed personal and medical data; the company says patient safety and operations are unaffected (SecurityAffairs).
· Threat Activity & Intelligence
in The Gentlemen Weaponize a Signed Kontron Driver Into an EDR Killswitch
July 5, 2026
- Fluke Corporation data tied to ShinyHunters' Salesforce campaign. A forum actor claims 21M+ Salesforce records (100GB+) with PII, attributed to ShinyHunters. Unverified. Daily Dark Web
· Data Breaches & Threat Intel
in Confidential Computing's Root of Trust May Be Unfixable
July 4, 2026
- Medtronic breach hits 3.8M people. The medtech firm is notifying patients that ShinyHunters accessed corporate IT systems in April and stole personal and medical data; the company says device safety was unaffected. SecurityWeek
· Threat Intelligence
in Silent Active Directory Recon and a Near-Perfect Linux Root Exploit Lead the Offensive Beat
July 2, 2026
- Medtronic is notifying customers affected by a ShinyHunters breach; the group also listed Ingram Content Group and Fluke Corporation (previously named by Clop in 2025) on its leak site. BleepingComputer.
· Data Breaches
in Scattered Spider Suspect Grabbed at Helsinki Airport, Extradited to the US
June 30, 2026
- NAIC confirmed a breach by ShinyHunters via an Oracle PeopleSoft zero-day (group claims 3.1 TB stolen); Nissan disclosed an employee-data breach tied to the same PeopleSoft exploitation campaign. NAIC, Nissan
· Threat Activity
in Edge Appliances Bleed: watchTowr Drops Kemp LoadMaster Pre-Auth RCE as Oracle EBS Joins the Exploited List
June 28, 2026
- NAIC confirmed a cyberattack exploiting an Oracle PeopleSoft zero-day; ShinyHunters claims 3.1TB of data theft, though the organization disputes the scope. SC Media
· Breaches & Data Exposure
in A WHQL-Signed Kernel Backdoor Hides in a WFP Callout as a "Clean" GitHub Repo Pwns AI Coding Agents
June 20, 2026
- ShinyHunters added more high-profile victims, including the Council of Europe, where it claims a 297GB theft via an Oracle PeopleSoft zero-day. The Register
· Ransomware & Extortion
in FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token
June 19, 2026
in FortiBleed Burns 70,000+ Fortinet Edge Devices While a Leaked GitHub Token Guts Novo Nordisk
June 18, 2026
- Oracle PeopleSoft CVE-2026-35273 unauthenticated RCE is under active exploitation by ShinyHunters (aka Bling Libra), with the education sector hit hardest since at least late May. Horizon3 confirmed exploitation predating disclosure, and Unit 42 corroborates the campaign against universities. watchTowr warns that "vibecoded" PoCs circulating are only the first-stage SSRF, not the full chain — treat public exploits skeptically (watchTowr).
· Vulnerabilities & Exploits
- Kodak confirmed a data breach claimed by ShinyHunters, working with external responders; scope not yet verified (BleepingComputer, SecurityWeek).
· Data Breaches (Nordic emphasis)
in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel
June 17, 2026
- Instructure Canvas breach hit 275 million students: ShinyHunters exploited stored XSS in the support-ticket system, enabled by poor content isolation and shared infrastructure. Scott Helme.
· Data Breaches & Extortion
- ShinyHunters added American Tower, JCPenney, Madison Square Garden Sports, Ralph Lauren, and Nexstar to its leak site (claims unverified), and separately claims a PeopleSoft zero-day heist of ~297GB from the Council of Europe. Kodak and Infinite Campus (137K school staff via Salesforce) also confirmed/were named in ShinyHunters incidents. Daily Dark Web, SecurityWeek, BleepingComputer.
· Data Breaches & Extortion
in Microsoft 365 Copilot 'SearchLeak' Enables One-Click Data Theft as Novo Nordisk Loses Internal AI Models to Extortionists