The StopAndProtect operation is a multi-component campaign combining ransomware and data theft. It uses a ClickFix social engineering technique to deliver .NET-based loaders, which deploy ransomware, an SMB/USB worm, a lockscreen, a credential stealer, and a chat utility. The actors abuse thousands of compromised WordPress sites as infrastructure for hosting malware, C2 communication, and storing exfiltrated victim data.
Data Theft
7 posts
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit Mandiant and Google Threat Intelligence Group identified an active extortion campaign by UNC6240 (ShinyHunters) exploiting CVE-2026-35273, a critical zero-day RCE vulnerability in Oracle PeopleSoft. The threat actors targeted the higher education sector, deploying customized MeshCentral agents for C2 and utilizing custom scripts for lateral movement, defacement, and data exfiltration.
Now Live: The CrowdStrike 2026 Financial Services Threat Landscape Report The CrowdStrike 2026 Financial Services Threat Landscape Report highlights a 43% global increase in hands-on-keyboard intrusions against the financial sector. The threat landscape is dominated by eCrime ransomware operations, DPRK-nexus cryptocurrency theft via supply chain compromises, and China-nexus intelligence collection leveraging Operational Relay Box (ORB) networks and DLL search-order hijacking.
Canvas Attackers Compromise 275M Students, Teachers, and Staff The threat group ShinyHunters compromised Instructure's Canvas learning management system, likely via voice phishing (vishing) targeting their interconnected Salesforce environment. The breach resulted in the theft of 3.65 TB of sensitive data affecting 275 million users, which the actors are now leveraging in an active extortion campaign and which poses a severe downstream phishing risk.
Defending Against CORDIAL SPIDER and SNARKY SPIDER with Falcon Shield CORDIAL SPIDER and SNARKY SPIDER are executing rapid, SaaS-centric data theft and extortion campaigns by leveraging vishing and AiTM phishing pages. By capturing session tokens and authentication data, these actors bypass traditional endpoint defenses and pivot directly into SSO-integrated SaaS environments via the organization's Identity Provider (IdP).
What You Need To Know About Salesforce AuraInspector Attacks The threat actor ShinyHunters is leveraging a modified version of the AuraInspector tool to exploit misconfigured Salesforce Experience sites. By targeting overly permissive guest user profiles, attackers can interact with backend Aura endpoints to enumerate and exfiltrate sensitive corporate data without requiring authentication.
Silent Brothers | Ollama Hosts Form Anonymous AI Network Beyond Platform Guardrails A joint research project by SentinelLABS and Censys discovered a massive, unmanaged network of over 175,000 publicly exposed Ollama instances. Many of these self-hosted AI models possess tool-calling and vision capabilities, creating significant security risks such as resource hijacking, prompt injection, and identity laundering through residential proxy abuse.