ShinyHunters Leaks Charter Communications Data, Potentially Impacting 5 Million Customers
2026-05-31T14:51:43Z•6f52d9b6b5842fa1c8ee52e0192f26c315567315b0dc94a17170d5524805b842
android-rataptasocksbotnetbtmobcode-signingcredential-theftcve-2026-35616data-breachexploitextortionforticlientlaw-enforcementmalwaremalware-signing-as-a-servicemobile-malwarephishingrcerussia-linkedtakedownvulnerabilityzero-day
What happened
Feed of May 28–31, 2026 security incidents: threat actor ShinyHunters published alleged Charter Communications customer data (≈5M records) after failed extortion, and Carnival disclosed a breach exposing ~6M customers. A critical FortiClient EMS RCE (CVE-2026-35616, CVSS 9.1) is being actively exploited to deploy malware. Dutch authorities seized servers and dismantled a 17‑million‑device botnet linked to Asocks proxy service. Signal users (journalists/activists) are being phished for backup recovery keys to decrypt histories. WithSecure tracked GREYVIBE, a Russia-linked APT using AI-assisted攻
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 6f52d9b6b5842fa1c8ee52e0192f26c315567315b0dc94a17170d5524805b842
- Enrichment time
- 2026-05-31T14:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.