ShinyHunters hack 7-Eleven: franchisee data and Salesforce records exposed
2026-05-18T14:51:47Z•8ce0091748f6903abc75b37ef62c54b94bc41d579201c4e26e7ec4487352b0d9
APTPwn2OwnTurlaactive-exploitationbotnetcloud-misconfigurationdata-breache-skimmerexposed-datamicrosoft-exchangenginxprivilege-escalationvulnerability-researchwindowswordpresszero-day
What happened
This feed aggregates multiple high-impact security incidents and research from mid-May 2026: ShinyHunters claimed theft of over 600k Salesforce and franchisee records from 7‑Eleven; a misconfigured Amazon S3 bucket exposed over 1 million passports, IDs and verification selfies from Japanese hotel platform Tabiq; Chaotic Eclipse released a MiniPlasma Windows SYSTEM privilege-escalation exploit targeting cldflt.sys (linked to CVE-2020-17103 behavior); a critical NGINX flaw (CVE-2026-42945, CVSS ~9.2) is being actively exploited; CISA added Microsoft Exchange Server CVE-2026-42897 to its KEV list
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 8ce0091748f6903abc75b37ef62c54b94bc41d579201c4e26e7ec4487352b0d9
- Enrichment time
- 2026-05-18T14:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.