ShinyHunters alleges access to data from three breach paths: UNC6040, Salesforce Aura, and compromised AWS accounts, claiming over three million Salesforce records, PII, GitHub repositories, AWS storage, and internal corporate data were exfiltrated.
Researchers at watchTowr identified an authentication bypass (CVE-2026-2699) and a remote code execution flaw (CVE-2026-2701) within the Storage Zones Controller (SZC) component of Progress ShareFile versions 5.x.
Suspected Iran-linked hacktivist operation Nasir Security, also known as Nasir Resistance, has commenced exposing data allegedly pilfered following a months-long breach of the Dubai International Airport, according to Cybernews.
Cisco had over three million Salesforce records with personal information, AWS buckets, GitHub repositories, and other corporate information allegedly stolen by the ShinyHunters hacking operation across three separate cyberattacks, Cybernews reports.
The NoVoice operation, identified by McAfee, concealed malicious components within the com.facebook.utils package, blending them with legitimate Facebook SDK classes.
The study, detailed in a preprint paper by Standford University, University of California, Davis, and TU Delft researchers, utilized a tool called TruffleHog to scan websites.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.