daily cyber × ai intelligence

index

tagged

[shinyhunters]

33 editions · 36 items

September 14, 2026

  • Stolen police credentials opened Florida’s DAVID driver database. Florida says attackers used credentials taken from an officer’s personal device, The Record reports. BleepingComputer identifies the compromised account as belonging to a police-department employee with access to the FLHSMV system. ShinyHunters claims more than 2.8 million driver records, but the state’s confirmation establishes the access route, not necessarily the group’s full claimed scope. · Identity & Data Exposure

in Hermes Logs Reveal Unattended AI Post-Exploitation

September 13, 2026

  • Anthropic's 154-page report gains actor-level detail. The Russian state-sponsored cluster it calls GTG-20006 — sharing tradecraft with Midnight Blizzard/APT29 — built an AI-assisted workflow to rebuild malware after detection, in a campaign against more than 20 government, intelligence, diplomatic and defence organisations (The Hacker News, The Record). GTG-50014 (aka MeowSHA), a French-speaking suspected ShinyHunters affiliate, ran 10 AWS EC2 workers that pulled 1.8 million distinct Android APKs, scanned them with TruffleHog and pushed verified secrets to Telegram; a second ShinyHunters affiliate hit SaaS vendors to reach roughly 50 downstream organisations and maintained an autonomous vulnerability-research programme producing working exploits for unknown flaws in network and security appliances (The Hacker News, earlier coverage). Anthropic also describes users in Houthi-held Yemen attempting weapons development, including a failed guided-rocket test, without fielding an operational device (SecurityWeek). Worth reading the caveats: @cyb3rops notes the "sandbox escape" was internet access enabled by a misconfiguration, not a VM or container escape, and the "safety monitor" was another LLM reviewing transcripts after the fact. · AI-Enabled Threat Activity

in Artifactory Chains Give Attackers Admin in Under Five Minutes

September 11, 2026

  • Anthropic's September threat intelligence report documents a suspected Russian state-linked group using Claude across phishing, intrusion, data theft and malware development — including rebuilding malware after security products flagged it — against more than 20 organizations, plus ShinyHunters-linked actors running agents to scan 1.8 million Android apps. The framing is that AI is moving from advice into the operational loop: recon, exploitation, credential theft, persistence and victim-data triage (Anthropic). Practitioners are not uniformly sold: @keyth0s argues Anthropic's classifiers are "pretty bad for cyber dual use things" and easy to trip without real evidence (discussion). · Offensive AI in the Wild
  • AdaptHealth put the count at 4,115,802 individuals in its HHS filing. Entry was on 5 June through social engineering that compromised a third-party contractor's privileged account; a ransom demand followed on 15 June. ShinyHunters was named by HIPAA Journal, though the company's entry has since vanished from the group's portal (BleepingComputer). · Breaches

in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign

September 8, 2026

  • ShinyHunters claims a breach of the Florida DMV, using Jeffrey Epstein's driver's licence record as the public proof sample on its pay-or-leak site (vx-underground); Dark Web Informer suggests the licence data may have been bought from the Nexus market actor rather than stolen directly. In the Netherlands, police broadcast the Odido vishing suspect's voice on Opsporing Verzocht on 7 September: a Dutch-speaking man phoned customer service posing as an IT-department colleague and an employee unintentionally granted him access to an internal system, exposing data on more than six million customers. A voice expert concluded it is a real human voice, not AI-generated, and noted the caller's fluent English IT jargon suggests helpdesk experience (Dutch National Police). A ~100 GB Odido dataset is now being distributed publicly rather than sold (Daily Dark Web). · Threat Activity
  • Mathspace says 1,079,819 students, staff and parents in Australia and New Zealand had data stolen after attackers exploited a vulnerability in its self-hosted Metabase install to gain administrator access without a login. Access began 10 August, the Australian reporting database was downloaded 27 August, and the theft was confirmed 3 September; no academic records, password hashes, tokens or SSO credentials were exposed (BleepingComputer) — the latest in the run of Metabase SQL injection zero-day intrusions linked to ShinyHunters. · Breaches

in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited

July 27, 2026

  • ShinyHunters leak data is fueling a $2,000 sextortion campaign. Scammers are mining email addresses from previously dumped datasets — attributed to Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill — to send targeted-looking Bitcoin demands; BleepingComputer confirmed some recipients appeared in the referenced dumps (BleepingComputer). · Threat Activity

in Two Live Exploits and a Bench of Fresh Offensive Tooling

July 7, 2026

A 16-Year-Old KVM Flaw Punches Through the Hypervisor Boundary

A 16-year-old KVM hypervisor vulnerability (CVE-2026-53359) enabling guest-to-host escape is under public exploitation, with panic PoCs already available. Adobe ColdFusion CVE-2026-48282 (CVSS 10.0) is being actively exploited in the wild within hours of disclosure, with unauthenticated remote code execution possible. AI-powered coding agents are now a live attack surface, with researchers demonstrating agent hijacking, malicious skill injection, and data exfiltration through prompt injection in creator tools like YouTube's Ask Studio. Iran-linked hackers are deploying a new modular C2 framework called Cavern against Israeli targets, while ClickFix malware operators are leveraging blockchain as a resilient command infrastructure.

June 18, 2026

  • Oracle PeopleSoft CVE-2026-35273 unauthenticated RCE is under active exploitation by ShinyHunters (aka Bling Libra), with the education sector hit hardest since at least late May. Horizon3 confirmed exploitation predating disclosure, and Unit 42 corroborates the campaign against universities. watchTowr warns that "vibecoded" PoCs circulating are only the first-stage SSRF, not the full chain — treat public exploits skeptically (watchTowr). · Vulnerabilities & Exploits
  • Kodak confirmed a data breach claimed by ShinyHunters, working with external responders; scope not yet verified (BleepingComputer, SecurityWeek). · Data Breaches (Nordic emphasis)

in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel

June 17, 2026

  • Instructure Canvas breach hit 275 million students: ShinyHunters exploited stored XSS in the support-ticket system, enabled by poor content isolation and shared infrastructure. Scott Helme. · Data Breaches & Extortion
  • ShinyHunters added American Tower, JCPenney, Madison Square Garden Sports, Ralph Lauren, and Nexstar to its leak site (claims unverified), and separately claims a PeopleSoft zero-day heist of ~297GB from the Council of Europe. Kodak and Infinite Campus (137K school staff via Salesforce) also confirmed/were named in ShinyHunters incidents. Daily Dark Web, SecurityWeek, BleepingComputer. · Data Breaches & Extortion

in Microsoft 365 Copilot 'SearchLeak' Enables One-Click Data Theft as Novo Nordisk Loses Internal AI Models to Extortionists