ShinyHunters Leaks Charter Communications Data, Potentially Impacting 5 Million Customers

2026-05-31T14:51:43Z6f52d9b6b5842fa1c8ee52e0192f26c315567315b0dc94a17170d5524805b842
android-rataptasocksbotnetbtmobcode-signingcredential-theftcve-2026-35616data-breachexploitextortionforticlientlaw-enforcementmalwaremalware-signing-as-a-servicemobile-malwarephishingrcerussia-linkedtakedownvulnerabilityzero-day

What happened

Feed of May 28–31, 2026 security incidents: threat actor ShinyHunters published alleged Charter Communications customer data (≈5M records) after failed extortion, and Carnival disclosed a breach exposing ~6M customers. A critical FortiClient EMS RCE (CVE-2026-35616, CVSS 9.1) is being actively exploited to deploy malware. Dutch authorities seized servers and dismantled a 17‑million‑device botnet linked to Asocks proxy service. Signal users (journalists/activists) are being phished for backup recovery keys to decrypt histories. WithSecure tracked GREYVIBE, a Russia-linked APT using AI-assisted攻

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
6f52d9b6b5842fa1c8ee52e0192f26c315567315b0dc94a17170d5524805b842
Enrichment time
2026-05-31T14:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.