Sunday , August 16 2026

ShinyHunters Launches Data Leak Site Listing Salesforce Breach

The Trinity of Chaos, a ransomware group linked to Lapsus$, Scattered Spider, and ShinyHunters, has created a Data Leak Site on the TOR network. This site includes data from 39 companies, such as Aeromexico, AirFrance, Google, Cisco, Stellantis, and Qantas Airlines, affected by attacks on weak Salesforce instances and other vulnerabilities.

Trinity of Chaos, a ransomware collective presumably associated with Lapsus$, Scattered Spider, and ShinyHunters. Resecurity’s previous report indicates that the group will continue its activities, now focusing on traditional ransomware.

NIST to Modernize NVD in the Age of Artificial Intelligence

National Institute of Standards and Technology (NIST) demands feedback from industry and the government on how to update the National...
Read More
NIST to Modernize NVD in the Age of Artificial Intelligence

ALERT
Multiple TP-Link Flaws Allow to Bypass Auth and Escalate Privileges

TP-Link has revealed several serious security flaws in Aginet networking products managed by ISPs. This includes mesh systems, routers, PON...
Read More
ALERT  Multiple TP-Link Flaws Allow to Bypass Auth and Escalate Privileges

LiteLLM supply chain attack reveals 153GB of stolen credentials online

153GB record surface online stolen during the LiteLLM supply chain attack linked to thousands of corporate domains, including AWS, Samsung,...
Read More
LiteLLM supply chain attack reveals 153GB of stolen credentials online

PATCHCORD Backdoor Targets Telecom and CII In South Asia

A previously undocumented backdoor called PATCHCORD actively target telecom and critical information infrastructure (CII) in South Asia. According to Acronis...
Read More
PATCHCORD Backdoor Targets Telecom and CII In South Asia

Fortinet Fixes Multiple Flaws in FortiWeb, FortiManager, and FortiClient

Fortinet has released fixes for a set of authentication flaws in its FortiWeb, FortiManager, and FortiClient products. It warns admins...
Read More
Fortinet Fixes Multiple Flaws in FortiWeb, FortiManager, and FortiClient

“City-Forum” Campaign
“City-Forum” Campaign Attacks Salesforce and ServiceNow Instances Worldwide

A data theft plan is stealing information from anonymous users on Salesforce Experience Cloud and ServiceNow customer portals using special...
Read More
“City-Forum” Campaign  “City-Forum” Campaign Attacks Salesforce and ServiceNow Instances Worldwide

Palo Alto Patches 11 New flaws Across PAN-OS, GlobalProtect, and Prisma Access

Palo Alto Networks shared its security bulletin revealing 11 new issues that impact PAN-OS, the GlobalProtect App, Prisma Access Agent,...
Read More
Palo Alto Patches 11 New flaws Across PAN-OS, GlobalProtect, and Prisma Access

CVE-2026-20349, CVE-2026-68820
Cisco and Windows patched zero days exploited in attack

Cisco warns customers that it has fixed a serious security hole in firewalls using Secure Firewall Adaptive Security Appliance (ASA)...
Read More
CVE-2026-20349, CVE-2026-68820  Cisco and Windows patched zero days exploited in attack

Microsoft Patch 394 Flaws, Including 3 Zero-Days

Microsoft announced fixes for 394 CVEs on Tuesday, including a serious flaw that has been used by hackers as a...
Read More
Microsoft Patch 394 Flaws, Including 3 Zero-Days

AI Finds Nation-State-Level Zoom Flaw in Under 24 Hours, Zero-Click Attack Exposed

A serious security flaw in Zoom might let a hacker take control of someone else's device in a live meeting...
Read More
AI Finds Nation-State-Level Zoom Flaw in Under 24 Hours, Zero-Click Attack Exposed

The Data Leak Site (DLS) lists recent victims like Stellantis, which revealed a data breach affecting North American customers on September 21, 2025. This followed an attack on Jaguar Land Rover that disrupted its retail and production.

Most leaked data samples don’t include passwords but have a lot of PII, suggesting they probably come from compromised Salesforce instances due to vishing attacks and stolen OAuth tokens linked to Salesloft’s Drift AI chat integration. This has led the FBI to issue a flash warning with technical indicators for organizations to check for potential intrusions in their Salesforce systems.

A Resecurity report has revealed a growing global cybercrime campaign led by LAPSUS$, ShinyHunters, and Scattered Spider. Despite claims of their “retirement,” this group continues to hack and extort large companies, with many significant data breaches still undisclosed. The report indicates an increase in private extortion efforts, suggesting the real impact of these hackers may be much larger than known. They also claim to have updated the Data Leak Site (DLS) after October 10, which now features over 1.5 billion records.

Resecurity analysts indicate that new victims and incidents are now surfacing. Ongoing extortion activities and the group’s reputation are pressuring companies to remain silent, revealing the extent of compromised data in the Fortune 100, financial, technology, aviation, retail, and auto sectors.

Cybersecurity experts warn that cybercriminals could use stolen data for harmful purposes, including in AI applications. They can analyze victim information to gain insights and connect data sets, enabling sophisticated social engineering, targeted phishing, and identity theft, particularly against large businesses and government entities.

Check Also

exploited

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws …