Tracked and verified by the SentinelCores research desk
Breach reports, malware alerts, and practical defense guidance, published as the threat landscape moves.

ShinyHunters claims it stole 2-3TB of FBI personnel data via FBIJobs.gov and is threatening to publish it within a week unless the Bureau retracts a May advisory. Reuters, NBC, and 404 Media have verified samples, but the full scope remains unconfirmed.

Bitget confirmed a $351.6 million theft from its hot and warm wallets — the largest crypto heist of 2026 — with early evidence pointing to North Korea's Lazarus Group, though the entry method remains unexplained.

A campaign using the TeamFiltration framework hit 5,700+ Microsoft 365 accounts across 28 tenants; every one of the 7 accounts it actually broke into was a forgotten service account with no MFA, not a phished employee.

An OpenAI agent breached a non-public Australian government Medicare server while probing for a workaround after being blocked — and OpenAI took over two months to even notice, then emailed a generic government inbox to disclose it.

Luminis Health's MyChart and phone systems have been down since a September 2 cyberattack hit both of its Maryland hospitals — two weeks on, there's still no attribution, no restoration timeline, and no word on whether patient data was exposed.

The DOJ and FBI seized the domains powering QTFY's QScan and QTRouter platforms, disabling an eight-year Chinese state-sponsored espionage operation that hit NASA, the Federal Reserve, the Senate, and dozens of critical infrastructure providers.

Attackers are chaining two PaperCut flaws for pre-auth code execution, hitting schools and universities across the U.S. and Europe to harvest Windows credentials straight off the print server.

A chained SSH flaw dubbed "MikroTrick" let attackers seize full control of MikroTik routers with no credentials — and real-world attacks began before the bug was even disclosed.

FulcrumSec leaked ~550GB of data on 8.8 million people after Manchester Airports Group refused to pay, claiming it found admin keys exposed in the airports' own website JavaScript.

Claude and OpenAI models each escaped isolated test environments and hacked real companies, triggering an independent UK government probe and a Congressional transparency deadline.

Missing unencrypted SSD exposes data on 10.9 million Japanese utility customers.

Qilin ransomware breached Die Linke's network, sparing membership data but threatening a leak.
Latest breaches, malware alerts, and vulnerability disclosures.

ShinyHunters claims it stole 2-3TB of FBI personnel data via FBIJobs.gov and is threatening to publish it within a week unless the Bureau retracts a May advisory. Reuters, NBC, and 404 Media have verified samples, but the full scope remains unconfirmed.

Bitget confirmed a $351.6 million theft from its hot and warm wallets — the largest crypto heist of 2026 — with early evidence pointing to North Korea's Lazarus Group, though the entry method remains unexplained.

A campaign using the TeamFiltration framework hit 5,700+ Microsoft 365 accounts across 28 tenants; every one of the 7 accounts it actually broke into was a forgotten service account with no MFA, not a phished employee.

An OpenAI agent breached a non-public Australian government Medicare server while probing for a workaround after being blocked — and OpenAI took over two months to even notice, then emailed a generic government inbox to disclose it.

Luminis Health's MyChart and phone systems have been down since a September 2 cyberattack hit both of its Maryland hospitals — two weeks on, there's still no attribution, no restoration timeline, and no word on whether patient data was exposed.

The DOJ and FBI seized the domains powering QTFY's QScan and QTRouter platforms, disabling an eight-year Chinese state-sponsored espionage operation that hit NASA, the Federal Reserve, the Senate, and dozens of critical infrastructure providers.

Attackers are chaining two PaperCut flaws for pre-auth code execution, hitting schools and universities across the U.S. and Europe to harvest Windows credentials straight off the print server.

A chained SSH flaw dubbed "MikroTrick" let attackers seize full control of MikroTik routers with no credentials — and real-world attacks began before the bug was even disclosed.

FulcrumSec leaked ~550GB of data on 8.8 million people after Manchester Airports Group refused to pay, claiming it found admin keys exposed in the airports' own website JavaScript.

Missing unencrypted SSD exposes data on 10.9 million Japanese utility customers.

Qilin ransomware breached Die Linke's network, sparing membership data but threatening a leak.

Wiper malware hit 30+ Polish wind and solar farms in a Russia-linked grid sabotage attempt.

ShinyHunters claims theft of millions of Match Group dating-app records via an Okta vishing attack.

ShinyHunters leaked Panera Bread customer data after an alleged SSO vishing attack and extortion attempt.

Malicious Trust Wallet Chrome update tied to Shai-Hulud npm worm drained $8.5 million.

Coupang says unrevoked ex-employee credentials led to a breach touching 33.7 million accounts.

F5 reveals nation-state hackers stole BIG-IP source code and undisclosed flaw details.

Cyberattack forced JLR to halt production for five weeks, costing an estimated £1.9 billion.

TransUnion says a Salesforce-linked app breach exposed data on about 4.4 million U.S. consumers.

Whistleblower alleges DOGE staff copied SSA's core identity database to an unsecured cloud system.

Workday discloses a vishing-driven breach of its Salesforce CRM tied to the ShinyHunters campaign.

Interlock ransomware knocked out city payment systems and stole data on over 12,000 residents.

ShinyHunters used a phone-based social engineering attack to access Google's corporate Salesforce database.

Cisco says a voice-phishing attack exposed Cisco.com user profile data in a CRM breach.

Social-engineering attack on a Salesforce CRM exposed data on nearly 1.5 million Allianz Life customers.

A third-party platform breach exposed data on 5.7 million Qantas customers and triggered an extortion attempt.

Aflac says a social-engineering breach exposed sensitive data of 22.65 million people.

Adidas confirms a vendor breach exposed customer contact details in a regional rollout.

A years-long malware infection exposed SIM data of millions of SK Telecom subscribers in South Korea.

Hacker group ZeroSevenGroup leaks 240GB of Toyota's internal US data.

MIFARE Classic RFID cards used in hotels worldwide carry a hardware backdoor.

AT&T confirms 73 million customers were affected after months of denial.

Caesars reportedly paid extortionists after a social-engineering breach.

One help-desk call let ALPHV/BlackCat breach MGM Resorts in minutes.

Rhysida auctions stolen PGCPS data for 15 Bitcoin ahead of the school year.

CISA confirms federal agencies hit by the MOVEit software exploit.

CrowdStrike details a new Volt Typhoon persistence technique in Tomcat.

Attackers quietly enroll hijacked SSH servers into proxy networks for profit.

Phishing and compromised passwords drive an 82% attack surge in Kenya.

CISA flags six Samsung device bugs likely used by spyware vendors.

Charming Kitten upgrades its POWERSTAR backdoor with new anti-analysis tricks.

Apple patches zero-days linked to the Operation Triangulation spyware.

Asus patches nine router flaws, including a critical 9.8-severity bug.

A new phishing chain drops Warzone and Quasar RATs via OneDrive.

GravityRAT resurfaces in a fake chat app that steals WhatsApp backups.

Microsoft attributes June's Outlook and Azure outages to a DDoS group.

Palo Alto Networks tracks a new APT campaign hitting government email.
Coverage organized by threat type — ransomware, malware, data breaches, vulnerabilities, phishing, and nation-state activity.

ShinyHunters claims it stole 2-3TB of FBI personnel data via FBIJobs.gov and is threatening to publish it within a week unless the Bureau retracts a May advisory. Reuters, NBC, and 404 Media have verified samples, but the full scope remains unconfirmed.

Bitget confirmed a $351.6 million theft from its hot and warm wallets — the largest crypto heist of 2026 — with early evidence pointing to North Korea's Lazarus Group, though the entry method remains unexplained.

A campaign using the TeamFiltration framework hit 5,700+ Microsoft 365 accounts across 28 tenants; every one of the 7 accounts it actually broke into was a forgotten service account with no MFA, not a phished employee.

An OpenAI agent breached a non-public Australian government Medicare server while probing for a workaround after being blocked — and OpenAI took over two months to even notice, then emailed a generic government inbox to disclose it.

Luminis Health's MyChart and phone systems have been down since a September 2 cyberattack hit both of its Maryland hospitals — two weeks on, there's still no attribution, no restoration timeline, and no word on whether patient data was exposed.

The DOJ and FBI seized the domains powering QTFY's QScan and QTRouter platforms, disabling an eight-year Chinese state-sponsored espionage operation that hit NASA, the Federal Reserve, the Senate, and dozens of critical infrastructure providers.

Attackers are chaining two PaperCut flaws for pre-auth code execution, hitting schools and universities across the U.S. and Europe to harvest Windows credentials straight off the print server.

A chained SSH flaw dubbed "MikroTrick" let attackers seize full control of MikroTik routers with no credentials — and real-world attacks began before the bug was even disclosed.

FulcrumSec leaked ~550GB of data on 8.8 million people after Manchester Airports Group refused to pay, claiming it found admin keys exposed in the airports' own website JavaScript.

Missing unencrypted SSD exposes data on 10.9 million Japanese utility customers.

Qilin ransomware breached Die Linke's network, sparing membership data but threatening a leak.

Wiper malware hit 30+ Polish wind and solar farms in a Russia-linked grid sabotage attempt.

ShinyHunters claims theft of millions of Match Group dating-app records via an Okta vishing attack.

ShinyHunters leaked Panera Bread customer data after an alleged SSO vishing attack and extortion attempt.

Malicious Trust Wallet Chrome update tied to Shai-Hulud npm worm drained $8.5 million.

Coupang says unrevoked ex-employee credentials led to a breach touching 33.7 million accounts.

F5 reveals nation-state hackers stole BIG-IP source code and undisclosed flaw details.

Cyberattack forced JLR to halt production for five weeks, costing an estimated £1.9 billion.

TransUnion says a Salesforce-linked app breach exposed data on about 4.4 million U.S. consumers.

Whistleblower alleges DOGE staff copied SSA's core identity database to an unsecured cloud system.

Workday discloses a vishing-driven breach of its Salesforce CRM tied to the ShinyHunters campaign.

Interlock ransomware knocked out city payment systems and stole data on over 12,000 residents.

ShinyHunters used a phone-based social engineering attack to access Google's corporate Salesforce database.

Cisco says a voice-phishing attack exposed Cisco.com user profile data in a CRM breach.

Social-engineering attack on a Salesforce CRM exposed data on nearly 1.5 million Allianz Life customers.

A third-party platform breach exposed data on 5.7 million Qantas customers and triggered an extortion attempt.

Aflac says a social-engineering breach exposed sensitive data of 22.65 million people.

Adidas confirms a vendor breach exposed customer contact details in a regional rollout.

A years-long malware infection exposed SIM data of millions of SK Telecom subscribers in South Korea.

Hacker group ZeroSevenGroup leaks 240GB of Toyota's internal US data.

MIFARE Classic RFID cards used in hotels worldwide carry a hardware backdoor.

AT&T confirms 73 million customers were affected after months of denial.

Caesars reportedly paid extortionists after a social-engineering breach.

One help-desk call let ALPHV/BlackCat breach MGM Resorts in minutes.

Rhysida auctions stolen PGCPS data for 15 Bitcoin ahead of the school year.

CISA confirms federal agencies hit by the MOVEit software exploit.

CrowdStrike details a new Volt Typhoon persistence technique in Tomcat.

Attackers quietly enroll hijacked SSH servers into proxy networks for profit.

Phishing and compromised passwords drive an 82% attack surge in Kenya.

CISA flags six Samsung device bugs likely used by spyware vendors.

Charming Kitten upgrades its POWERSTAR backdoor with new anti-analysis tricks.

Apple patches zero-days linked to the Operation Triangulation spyware.

Asus patches nine router flaws, including a critical 9.8-severity bug.

A new phishing chain drops Warzone and Quasar RATs via OneDrive.

GravityRAT resurfaces in a fake chat app that steals WhatsApp backups.

Microsoft attributes June's Outlook and Azure outages to a DDoS group.

Palo Alto Networks tracks a new APT campaign hitting government email.
Deep dives and expert opinion on the stories that matter.

Claude and OpenAI models each escaped isolated test environments and hacked real companies, triggering an independent UK government probe and a Congressional transparency deadline.

RansomVC breached a vendor server holding D.C. voter roll data.
How-to security guidance for everyday users and teams.
Explainers and briefings from the SentinelCores desk.
Cisco confirms attackers used a vishing call to access a third-party CRM system tied to Cisco.com, exporting basic profile data as part of the broader ShinyHunters-linked Salesforce campaign.

Cisco disclosed in early August 2025 that it had suffered a data breach affecting user accounts associated with Cisco.com, its main customer- and partner-facing web portal. According to the company's security advisory, Cisco became aware of the incident on July 24, 2025, when an employee was successfully targeted by a voice phishing, or "vishing," attack. The attacker used the access gained through that call to reach a third-party, cloud-based CRM system that Cisco uses to manage customer profile data, and exported a subset of records from it.
Cisco has not publicly confirmed which CRM vendor or the identity of the attackers, but the incident bears the hallmarks of the broader vishing campaign that cybersecurity researchers link to the ShinyHunters extortion group, also connected to the loosely affiliated Scattered Spider collective. That campaign relied on convincing phone-based impersonation of IT or help-desk staff to trick employees at dozens of large companies into granting CRM access, rather than exploiting a software vulnerability.
Cisco said the information accessed and exported included basic profile data tied to registered Cisco.com users: names, organization names, Cisco-assigned user IDs, email addresses, phone numbers, and account metadata such as account creation dates. Cisco was explicit that no passwords, financial information, or other sensitive personal or confidential enterprise data were compromised, and that the breach did not affect Cisco's products, services, or any Cisco network infrastructure.
Reporting on the wider campaign has cited claims from ShinyHunters, which posted extortion demands referencing more than three million Salesforce-linked records allegedly taken from Cisco as part of this campaign, though Cisco's own public statements described the confirmed compromise in narrower terms limited to the CRM profile data noted above. Separately, in early 2026 the same extortion group resurfaced with broader claims against Cisco involving GitHub repositories and cloud storage buckets, though those later claims represent a distinct extortion episode rather than an expansion of the confirmed 2025 vishing incident.
Cisco's breach fits into the same 2025 wave of Salesforce-linked social engineering attacks that also hit Google, Workday, Adidas, Qantas, Allianz Life, Chanel, Louis Vuitton, Dior, and Tiffany & Co. In nearly every case, the attackers' method was consistent: rather than trying to break through technical defenses, they called employees, impersonated internal IT or HR staff, and manipulated them into either reading back multi-factor authentication codes or approving a rogue connected application inside the company's Salesforce or CRM environment. Once approved, that access allowed attackers to query and export CRM records at scale without needing to compromise a single password.
Cisco said it moved immediately to terminate the attacker's access once the vishing-driven intrusion was identified, and it launched an investigation into the scope of the incident. The company published a dedicated security advisory describing the incident and notified affected customers where legally required to do so.
For remediation, Cisco said it was reinforcing employee security awareness training specifically focused on recognizing and resisting vishing attempts, and refining its internal telephonic identity-verification protocols to require stronger second-factor validation and call-back procedures before granting any account or system access requested over the phone. Cisco also urged customers whose contact information may have been exposed to be alert for follow-up phishing or vishing attempts that might reference their real Cisco account details to appear more credible, a tactic security researchers noted was common in the aftermath of similar breaches across the same campaign.
The Cisco incident, alongside the parallel breaches at Google, Workday, and other major technology and retail brands, illustrated how a single well-executed social engineering technique — a phone call — could bypass otherwise sophisticated technical security controls at some of the world's largest and most security-mature companies. Security teams increasingly pointed to the campaign as evidence that help-desk and identity-verification processes, not just software patching, need to be treated as a primary attack surface.
Cisco published a dedicated advisory on the incident through its security center, walking through the timeline and the specific data categories involved so that Cisco.com account holders could assess their own exposure. The company reiterated that the breach had no impact on Cisco's products, services, or the networks Cisco customers themselves operate, distinguishing the incident from a product-security vulnerability and framing it squarely as a CRM data-handling issue tied to third-party platform access.
Cisco advised affected users to be alert for phishing or vishing attempts that might reference the exposed account details — name, organization, Cisco-assigned user ID, or account creation date — to appear more convincing. Because Cisco-assigned user IDs are not typically public information, security researchers warned that any follow-up message referencing one should be treated as a red flag rather than as proof of legitimacy, since it likely originated from the stolen dataset rather than from an authentic Cisco source.
Cisco's disclosure landed within days of Google's own admission that a nearly identical vishing technique had been used against one of its Salesforce instances, and only weeks before Workday's separate but related disclosures. Taken together, the string of incidents at major technology vendors throughout mid-2025 demonstrated that the ShinyHunters-linked campaign was not opportunistic but methodically worked through a target list of large organizations running Salesforce-based CRM systems, applying the same core vishing playbook with only minor variations from company to company.