ShinyHunters hack 7-Eleven: franchisee data and Salesforce records exposed

2026-05-18T14:51:47Z8ce0091748f6903abc75b37ef62c54b94bc41d579201c4e26e7ec4487352b0d9
APTPwn2OwnTurlaactive-exploitationbotnetcloud-misconfigurationdata-breache-skimmerexposed-datamicrosoft-exchangenginxprivilege-escalationvulnerability-researchwindowswordpresszero-day

What happened

This feed aggregates multiple high-impact security incidents and research from mid-May 2026: ShinyHunters claimed theft of over 600k Salesforce and franchisee records from 7‑Eleven; a misconfigured Amazon S3 bucket exposed over 1 million passports, IDs and verification selfies from Japanese hotel platform Tabiq; Chaotic Eclipse released a MiniPlasma Windows SYSTEM privilege-escalation exploit targeting cldflt.sys (linked to CVE-2020-17103 behavior); a critical NGINX flaw (CVE-2026-42945, CVSS ~9.2) is being actively exploited; CISA added Microsoft Exchange Server CVE-2026-42897 to its KEV list

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
8ce0091748f6903abc75b37ef62c54b94bc41d579201c4e26e7ec4487352b0d9
Enrichment time
2026-05-18T14:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.