<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #ShinyHunters</title><description>Cybersecurity articles tagged #ShinyHunters on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>ShinyHunters: Dark Reading on Potential ReliaQuest Breach</title><link>https://runtimerebel.com/blog/shinyhunters-dark-reading-on-potential-reliaquest-breach</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-dark-reading-on-potential-reliaquest-breach</guid><description>Dark Reading editors discuss the latest activities of the ShinyHunters threat group, including inquiries into a potential breach affecting ReliaQuest.</description><pubDate>Fri, 04 Sep 2026 12:24:21 GMT</pubDate><category>ShinyHunters</category><category>Data Breach</category><category>Cybercrime</category><category>Threat Intelligence</category><category>Dark Reading</category></item><item><title>ShinyHunters Breaches ReliaQuest Identity Dashboard via Phishing</title><link>https://runtimerebel.com/blog/shinyhunters-breaches-reliaquest-identity-dashboard-via-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-breaches-reliaquest-identity-dashboard-via-phishing</guid><description>ReliaQuest confirms ShinyHunters gained brief, view-only access to its identity dashboard via a sophisticated social engineering attack.</description><pubDate>Tue, 25 Aug 2026 00:41:55 GMT</pubDate><category>ShinyHunters</category><category>Social Engineering</category><category>Phishing</category><category>Credential Theft</category><category>Okta</category></item><item><title>ReliaQuest Thwarts ShinyHunters Social Engineering Attack on Okta SSO</title><link>https://runtimerebel.com/blog/reliaquest-thwarts-shinyhunters-social-engineering-attack-on-okta-sso</link><guid isPermaLink="true">https://runtimerebel.com/blog/reliaquest-thwarts-shinyhunters-social-engineering-attack-on-okta-sso</guid><description>ReliaQuest confirms a social engineering attack by ShinyHunters targeting an employee&apos;s Okta SSO, blocked from accessing applications or customer data.</description><pubDate>Mon, 24 Aug 2026 16:25:26 GMT</pubDate><category>ShinyHunters</category><category>Social Engineering</category><category>Phishing</category><category>Vishing</category><category>Okta</category></item><item><title>RingCentral Data Breach Exposes 1.6M Users to ShinyHunters</title><link>https://runtimerebel.com/blog/ringcentral-data-breach-exposes-1-6m-users-to-shinyhunters</link><guid isPermaLink="true">https://runtimerebel.com/blog/ringcentral-data-breach-exposes-1-6m-users-to-shinyhunters</guid><description>RingCentral data breach impacts 1.6 million users after a sophisticated social engineering attack by ShinyHunters. Names, emails, addresses, and phone numbers exposed.</description><pubDate>Sat, 15 Aug 2026 16:14:41 GMT</pubDate><category>ShinyHunters</category><category>Data Breach</category><category>Social Engineering</category><category>Extortion</category><category>RingCentral</category></item><item><title>ShinyHunters Breaches ShipMonk: 14,000 Trezor Customers&apos; Data Exposed</title><link>https://runtimerebel.com/blog/shinyhunters-breaches-shipmonk-14000-trezor-customers-data-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-breaches-shipmonk-14000-trezor-customers-data-exposed</guid><description>ShinyHunters group breached shipping provider ShipMonk, exposing personal data of 14,000 Trezor customers via a Metabase SQL injection vulnerability.</description><pubDate>Fri, 14 Aug 2026 09:00:29 GMT</pubDate><category>Data Breach</category><category>ShinyHunters</category><category>SQL Injection</category><category>ShipMonk</category><category>Trezor</category></item><item><title>ShinyHunters Breaches Brinks Home, Threatens Data Leak</title><link>https://runtimerebel.com/blog/shinyhunters-breaches-brinks-home-threatens-data-leak</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-breaches-brinks-home-threatens-data-leak</guid><description>ShinyHunters claims a breach of Brinks Home systems, threatening to leak stolen data. This analysis covers the threat actor, potential impact, and mitigation.</description><pubDate>Thu, 30 Jul 2026 17:31:04 GMT</pubDate><category>ShinyHunters</category><category>Brinks Home</category><category>Data Breach</category><category>Data Leak</category><category>Extortion</category><category>Cybercrime</category></item><item><title>ShinyHunters Targeting Healthcare: Data Theft Surges, Health-ISAC Warns</title><link>https://runtimerebel.com/blog/shinyhunters-targeting-healthcare-data-theft-surges-health-isac-warns</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-targeting-healthcare-data-theft-surges-health-isac-warns</guid><description>Health-ISAC warns of increasing ShinyHunters data theft attacks on healthcare and med-tech organizations. Learn about TTPs and critical mitigations.</description><pubDate>Wed, 29 Jul 2026 20:57:58 GMT</pubDate><category>ShinyHunters</category><category>Healthcare</category><category>Data Theft</category><category>Health ISAC</category><category>Phishing</category><category>Data Exfiltration</category></item><item><title>ShinyHunters Claims Ernst &amp; Young Hack: Analysis of Third-Party Risks</title><link>https://runtimerebel.com/blog/shinyhunters-claims-ernst-young-hack-analysis-of-third-party-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-claims-ernst-young-hack-analysis-of-third-party-risks</guid><description>Ernst &amp; Young faces data theft claims from ShinyHunters following a breach of a third-party platform. Learn about the impact and vendor security mitigation.</description><pubDate>Wed, 29 Jul 2026 06:32:39 GMT</pubDate><category>ShinyHunters</category><category>Ernst Young</category><category>Third Party Risk</category><category>Data Exfiltration</category><category>Financial Services</category></item><item><title>ShinyHunters Data Leaks Fuel $2,000 Sextortion Phishing Campaign</title><link>https://runtimerebel.com/blog/shinyhunters-data-leaks-fuel-2000-sextortion-phishing-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-data-leaks-fuel-2000-sextortion-phishing-campaign</guid><description>Scammers are weaponizing personal data from ShinyHunters leaks to launch convincing sextortion campaigns demanding $2,000 in Bitcoin from victims.</description><pubDate>Sat, 25 Jul 2026 17:00:04 GMT</pubDate><category>ShinyHunters</category><category>Sextortion</category><category>Phishing</category><category>Data Breach</category><category>Social Engineering</category></item><item><title>Medtronic Breach: ShinyHunters Exfiltrates 3.8M Patient Records</title><link>https://runtimerebel.com/blog/medtronic-breach-shinyhunters-exfiltrates-3-8m-patient-records</link><guid isPermaLink="true">https://runtimerebel.com/blog/medtronic-breach-shinyhunters-exfiltrates-3-8m-patient-records</guid><description>Medtronic confirms a data breach by ShinyHunters impacting 3.8 million people, exposing personal and protected health information (PHI) from corporate IT systems.</description><pubDate>Fri, 03 Jul 2026 10:39:14 GMT</pubDate><category>Medtronic</category><category>ShinyHunters</category><category>Data Breach</category><category>Healthcare</category><category>PHI</category></item><item><title>Medtronic Data Breach: ShinyHunters Campaign Exposes Customer PII</title><link>https://runtimerebel.com/blog/medtronic-data-breach-shinyhunters-campaign-exposes-customer-pii</link><guid isPermaLink="true">https://runtimerebel.com/blog/medtronic-data-breach-shinyhunters-campaign-exposes-customer-pii</guid><description>Medtronic notifies customers of a data breach linked to ShinyHunters. Learn how cloud credential theft led to the exposure of patient and customer records.</description><pubDate>Thu, 02 Jul 2026 07:35:29 GMT</pubDate><category>Medtronic</category><category>ShinyHunters</category><category>Snowflake</category><category>PII</category><category>Cloud Security</category></item><item><title>ShinyHunters Breach NAIC via PeopleSoft Zero-Day: Public Data Stolen</title><link>https://runtimerebel.com/blog/shinyhunters-breach-naic-via-peoplesoft-zero-day-public-data-stolen</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-breach-naic-via-peoplesoft-zero-day-public-data-stolen</guid><description>ShinyHunters exploited an Oracle PeopleSoft zero-day to breach NAIC, exfiltrating public data, logs, and configuration files. Review PeopleSoft security.</description><pubDate>Tue, 30 Jun 2026 00:58:15 GMT</pubDate><category>ShinyHunters</category><category>NAIC</category><category>Oracle PeopleSoft</category><category>Zero-Day</category><category>Data Breach</category><category>Extortion Group</category></item><item><title>Nissan Breach: Oracle PeopleSoft Zero-Day Exploited by ShinyHunters</title><link>https://runtimerebel.com/blog/nissan-breach-oracle-peoplesoft-zero-day-exploited-by-shinyhunters</link><guid isPermaLink="true">https://runtimerebel.com/blog/nissan-breach-oracle-peoplesoft-zero-day-exploited-by-shinyhunters</guid><description>Nissan discloses a data breach impacting current and former employees, attributed to an exploited Oracle PeopleSoft zero-day vulnerability linked to the ShinyHunters…</description><pubDate>Tue, 30 Jun 2026 00:57:50 GMT</pubDate><category>Nissan</category><category>Oracle PeopleSoft</category><category>Data Breach</category><category>ShinyHunters</category><category>Zero-Day</category></item><item><title>Kodak Data Breach Confirmed: ShinyHunters Linked to Exfiltration</title><link>https://runtimerebel.com/blog/kodak-data-breach-confirmed-shinyhunters-linked-to-exfiltration</link><guid isPermaLink="true">https://runtimerebel.com/blog/kodak-data-breach-confirmed-shinyhunters-linked-to-exfiltration</guid><description>Kodak acknowledges a data breach after ShinyHunters claimed responsibility, with the threat actor reportedly exfiltrating sensitive company information.</description><pubDate>Thu, 18 Jun 2026 09:50:54 GMT</pubDate><category>Kodak</category><category>ShinyHunters</category><category>Data Breach</category><category>Exfiltration</category><category>Cyberattack</category></item><item><title>ShinyHunters Exploits Oracle ERP Zero-Day to Breach Higher Ed</title><link>https://runtimerebel.com/blog/shinyhunters-exploits-oracle-erp-zero-day-to-breach-higher-ed</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-exploits-oracle-erp-zero-day-to-breach-higher-ed</guid><description>ShinyHunters is exploiting an unpatched zero-day vulnerability in Oracle ERP software, targeting US higher education institutions for data theft.</description><pubDate>Sat, 13 Jun 2026 05:36:54 GMT</pubDate><category>ShinyHunters</category><category>Oracle ERP</category><category>Zero-Day</category><category>Higher Education</category><category>Data Theft</category></item><item><title>CVE-2026-35273: Oracle PeopleSoft RCE Exploited as Zero-Day by ShinyHunters</title><link>https://runtimerebel.com/blog/cve-2026-35273-oracle-peoplesoft-rce-exploited-as-zero-day-by-shinyhunters</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-35273-oracle-peoplesoft-rce-exploited-as-zero-day-by-shinyhunters</guid><description>Mandiant and GTIG identified ShinyHunters (UNC6240) exploiting CVE-2026-35273, a critical RCE in Oracle PeopleSoft, targeting higher education.</description><pubDate>Fri, 12 Jun 2026 09:42:34 GMT</pubDate><category>ShinyHunters</category><category>UNC6240</category><category>Oracle PeopleSoft</category><category>CVE-2026-35273</category><category>Zero-Day</category><category>RCE</category><category>Higher Education</category></item><item><title>Oracle PeopleSoft RCE via CVE-2026-35273 — Mitigation Guide</title><link>https://runtimerebel.com/blog/oracle-peoplesoft-rce-via-cve-2026-35273-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/oracle-peoplesoft-rce-via-cve-2026-35273-mitigation-guide</guid><description>ShinyHunters (UNC6240) exploited an Oracle PeopleSoft zero-day (CVE-2026-35273) to breach university networks and exfiltrate data for extortion purposes.</description><pubDate>Thu, 11 Jun 2026 20:55:48 GMT</pubDate><category>CVE-2026-35273</category><category>ShinyHunters</category><category>Oracle PeopleSoft</category><category>UNC6240</category><category>Extortion</category></item><item><title>CVE-2024-21319: PeopleSoft Auth Bypass Exploited by ShinyHunters</title><link>https://runtimerebel.com/blog/cve-2024-21319-peoplesoft-auth-bypass-exploited-by-shinyhunters</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-21319-peoplesoft-auth-bypass-exploited-by-shinyhunters</guid><description>Oracle PeopleSoft zero-day CVE-2024-21319, an authentication bypass, is being actively exploited by ShinyHunters. Patch PeopleSoft 8.59, 8.60, 8.61 now.</description><pubDate>Thu, 11 Jun 2026 17:25:15 GMT</pubDate><category>CVE-2024-21319</category><category>PeopleSoft</category><category>Oracle</category><category>ShinyHunters</category><category>Authentication Bypass</category><category>Zero-Day</category><category>CPU</category></item><item><title>University of Nottingham Confirms Breach After ShinyHunters Data Leak</title><link>https://runtimerebel.com/blog/university-of-nottingham-confirms-breach-after-shinyhunters-data-leak</link><guid isPermaLink="true">https://runtimerebel.com/blog/university-of-nottingham-confirms-breach-after-shinyhunters-data-leak</guid><description>The University of Nottingham confirms a data breach after the ShinyHunters group leaked over 450,000 records, highlighting risks to academic data security.</description><pubDate>Thu, 11 Jun 2026 09:39:20 GMT</pubDate><category>ShinyHunters</category><category>University of Nottingham</category><category>Higher Education</category><category>Data Exfiltration</category><category>PII Leak</category></item><item><title>ShinyHunters Leak 234 GB of DentaQuest Data Impacting 2.6 Million</title><link>https://runtimerebel.com/blog/shinyhunters-leak-234-gb-of-dentaquest-data-impacting-2-6-million</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-leak-234-gb-of-dentaquest-data-impacting-2-6-million</guid><description>The ShinyHunters extortion group leaked 234 GB of data from DentaQuest, impacting 2.6 million individuals. Learn about the risks and how to protect PHI.</description><pubDate>Fri, 05 Jun 2026 13:14:00 GMT</pubDate><category>ShinyHunters</category><category>DentaQuest</category><category>Data Leak</category><category>Extortion</category><category>Healthcare Security</category></item><item><title>Charter Communications Data Breach: Millions of Records Exposed</title><link>https://runtimerebel.com/blog/charter-communications-data-breach-millions-of-records-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/charter-communications-data-breach-millions-of-records-exposed</guid><description>ShinyHunters leaked data allegedly from Charter Communications, potentially exposing nearly 5 million customer records. Organizations must assess third-party risk.</description><pubDate>Fri, 29 May 2026 17:20:56 GMT</pubDate><category>ShinyHunters</category><category>Charter Communications</category><category>Data Breach</category><category>Extortion</category><category>Data Leak</category></item><item><title>Charter Communications Data Breach: 4.9 Million Accounts Exposed</title><link>https://runtimerebel.com/blog/charter-communications-data-breach-4-9-million-accounts-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/charter-communications-data-breach-4-9-million-accounts-exposed</guid><description>Charter Communications confirms a data breach affecting 4.9 million customer accounts after an extortion group targeted a third-party vendor&apos;s environment.</description><pubDate>Fri, 29 May 2026 09:18:18 GMT</pubDate><category>Charter Communications</category><category>Spectrum</category><category>ShinyHunters</category><category>Data Breach</category><category>Third Party Risk</category></item><item><title>Charter Data Breach Confirmed: ShinyHunters Extortion Threat</title><link>https://runtimerebel.com/blog/charter-data-breach-confirmed-shinyhunters-extortion-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/charter-data-breach-confirmed-shinyhunters-extortion-threat</guid><description>Charter Communications confirms a data breach following an extortion threat by ShinyHunters.</description><pubDate>Tue, 26 May 2026 20:46:11 GMT</pubDate><category>Charter Communications</category><category>ShinyHunters</category><category>Data Breach</category><category>Extortion</category><category>Telecommunications</category><category>Third Party Risk</category></item><item><title>7-Eleven Data Breach: 185,000 Records Leaked by ShinyHunters</title><link>https://runtimerebel.com/blog/7-eleven-data-breach-185000-records-leaked-by-shinyhunters</link><guid isPermaLink="true">https://runtimerebel.com/blog/7-eleven-data-breach-185000-records-leaked-by-shinyhunters</guid><description>Analysis of the 7-Eleven data breach involving threat actor ShinyHunters, impacting 185,000 users and exposing sensitive PII including dates of birth.</description><pubDate>Tue, 26 May 2026 13:13:00 GMT</pubDate><category>7 Eleven</category><category>ShinyHunters</category><category>PII Leak</category><category>Data Breach</category><category>Identity Theft</category></item><item><title>Security Brief: Data Breaches, ShinyHunters Activity, and App Flaws</title><link>https://runtimerebel.com/blog/security-brief-data-breaches-shinyhunters-activity-and-app-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/security-brief-data-breaches-shinyhunters-activity-and-app-flaws</guid><description>Analyzes recent security events: Nvidia cloud gaming data breach, FBI warning on ShinyHunters hacking Canvas, and critical flaws in Audi mobile applications.</description><pubDate>Fri, 15 May 2026 16:42:44 GMT</pubDate><category>NVIDIA</category><category>ShinyHunters</category><category>Audi</category><category>Data Breach</category><category>Mobile Security</category><category>Cloud Gaming</category><category>FBI</category></item><item><title>US House Committee Probes Instructure Following Canvas Cyberattacks</title><link>https://runtimerebel.com/blog/us-house-committee-probes-instructure-following-canvas-cyberattacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/us-house-committee-probes-instructure-following-canvas-cyberattacks</guid><description>The House Committee on Homeland Security seeks testimony from Instructure after the ShinyHunters group targeted the Canvas LMS, compromising student data.</description><pubDate>Wed, 13 May 2026 00:53:18 GMT</pubDate><category>Instructure</category><category>Canvas</category><category>ShinyHunters</category><category>Homeland Security</category><category>Student Data</category></item><item><title>ShinyHunters Extorts Instructure: 3.65TB Canvas LMS Data Breach Analysis</title><link>https://runtimerebel.com/blog/shinyhunters-extorts-instructure-3-65tb-canvas-lms-data-breach-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-extorts-instructure-3-65tb-canvas-lms-data-breach-analysis</guid><description>Instructure reaches an agreement with ShinyHunters after a massive 3.65TB data breach affecting Canvas LMS users across thousands of educational institutions.</description><pubDate>Tue, 12 May 2026 09:05:00 GMT</pubDate><category>Instructure</category><category>Canvas LMS</category><category>ShinyHunters</category><category>Data Extortion</category><category>Education Sector</category></item><item><title>ShinyHunters Claims Second Attack Against Instructure: PII at Risk</title><link>https://runtimerebel.com/blog/shinyhunters-claims-second-attack-against-instructure-pii-at-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-claims-second-attack-against-instructure-pii-at-risk</guid><description>The threat actor ShinyHunters has launched a second attack against Instructure, putting the PII of hundreds of millions of EdTech users at immediate risk.</description><pubDate>Sat, 09 May 2026 00:50:39 GMT</pubDate><category>ShinyHunters</category><category>Instructure</category><category>Canvas LMS</category><category>Data Breach</category><category>PII Leak</category></item><item><title>ShinyHunters Defaces Canvas Login Portals in Extortion Campaign</title><link>https://runtimerebel.com/blog/shinyhunters-defaces-canvas-login-portals-in-extortion-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-defaces-canvas-login-portals-in-extortion-campaign</guid><description>ShinyHunters breached Instructure, defacing Canvas login portals for numerous educational institutions, potentially impacting user credentials and initiating extortion.</description><pubDate>Fri, 08 May 2026 00:50:31 GMT</pubDate><category>ShinyHunters</category><category>Instructure</category><category>Canvas LMS</category><category>Extortion</category><category>Education Sector</category><category>Defacement</category><category>Credential Theft</category></item><item><title>Instructure Data Breach: ShinyHunters Exposes Education Sector Vendor Risk</title><link>https://runtimerebel.com/blog/instructure-data-breach-shinyhunters-exposes-education-sector-vendor-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/instructure-data-breach-shinyhunters-exposes-education-sector-vendor-risk</guid><description>Analysis of the Instructure data breach by ShinyHunters, impacting educational institutions using Canvas LMS and highlighting critical third-party vendor dependencies.</description><pubDate>Thu, 07 May 2026 00:51:22 GMT</pubDate><category>Instructure</category><category>Canvas LMS</category><category>ShinyHunters</category><category>Education Sector</category><category>Data Breach</category><category>Third Party Risk</category><category>Vendor Security</category></item><item><title>Instructure Data Breach: ShinyHunters Claims Theft of Employee Data</title><link>https://runtimerebel.com/blog/instructure-data-breach-shinyhunters-claims-theft-of-employee-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/instructure-data-breach-shinyhunters-claims-theft-of-employee-data</guid><description>Educational technology giant Instructure confirms an internal data breach after the ShinyHunters threat group claims to have stolen sensitive corporate data.</description><pubDate>Mon, 04 May 2026 00:50:54 GMT</pubDate><category>Instructure</category><category>ShinyHunters</category><category>Canvas LMS</category><category>Data Breach</category><category>Extortion</category></item><item><title>Medtronic Data Breach: ShinyHunters Claims 9 Million Records Stolen</title><link>https://runtimerebel.com/blog/medtronic-data-breach-shinyhunters-claims-9-million-records-stolen</link><guid isPermaLink="true">https://runtimerebel.com/blog/medtronic-data-breach-shinyhunters-claims-9-million-records-stolen</guid><description>Medtronic confirms a security breach after the ShinyHunters threat group claims to have exfiltrated 9 million records containing personal information.</description><pubDate>Tue, 28 Apr 2026 08:57:57 GMT</pubDate><category>Medtronic</category><category>ShinyHunters</category><category>Data Breach</category><category>PII Theft</category><category>Medical Technology</category></item><item><title>ADT Confirms Data Breach Amid ShinyHunters Extortion Threat</title><link>https://runtimerebel.com/blog/adt-confirms-data-breach-amid-shinyhunters-extortion-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/adt-confirms-data-breach-amid-shinyhunters-extortion-threat</guid><description>ADT confirms a data breach following a ShinyHunters extortion attempt. Customer data is at risk; security professionals must advise enhanced vigilance.</description><pubDate>Sat, 25 Apr 2026 00:43:18 GMT</pubDate><category>ADT</category><category>ShinyHunters</category><category>Data Breach</category><category>Extortion</category><category>Cybercrime</category><category>Threat Intelligence</category></item><item><title>Vercel Data Breach: ShinyHunters Claim Theft of Next.js Creator Data</title><link>https://runtimerebel.com/blog/vercel-data-breach-shinyhunters-claim-theft-of-next-js-creator-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/vercel-data-breach-shinyhunters-claim-theft-of-next-js-creator-data</guid><description>Vercel confirms a security incident following claims by ShinyHunters to sell stolen data for $2 million. Analyze the impact on Next.js and supply chains.</description><pubDate>Mon, 20 Apr 2026 08:54:09 GMT</pubDate><category>Vercel</category><category>Next Js</category><category>ShinyHunters</category><category>Data Breach</category><category>Supply Chain Security</category></item><item><title>McGraw Hill Data Breach: 13.5 Million Accounts Leaked by ShinyHunters</title><link>https://runtimerebel.com/blog/mcgraw-hill-data-breach-13-5-million-accounts-leaked-by-shinyhunters</link><guid isPermaLink="true">https://runtimerebel.com/blog/mcgraw-hill-data-breach-13-5-million-accounts-leaked-by-shinyhunters</guid><description>Threat actor ShinyHunters leaks 13.5 million McGraw Hill user records following a Salesforce environment breach. Includes password hashes and PII.</description><pubDate>Thu, 16 Apr 2026 12:33:08 GMT</pubDate><category>McGraw Hill</category><category>ShinyHunters</category><category>Salesforce Breach</category><category>Data Leak</category><category>Credential Harvesting</category></item><item><title>Rockstar Games Analytics Data Leaked via ShinyHunters Extortion</title><link>https://runtimerebel.com/blog/rockstar-games-analytics-data-leaked-via-shinyhunters-extortion</link><guid isPermaLink="true">https://runtimerebel.com/blog/rockstar-games-analytics-data-leaked-via-shinyhunters-extortion</guid><description>Rockstar Games analytics data has been leaked by the ShinyHunters group following a breach at third-party provider Anodot. Analysis of the supply chain risk.</description><pubDate>Mon, 13 Apr 2026 20:25:13 GMT</pubDate><category>Rockstar Games</category><category>ShinyHunters</category><category>Anodot</category><category>Data Leak</category><category>Supply Chain</category></item><item><title>TeamPCP Supply Chain Campaign: Cisco Source Code Stolen, UNC6780 Activity</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-campaign-cisco-source-code-stolen-unc6780-activity</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-campaign-cisco-source-code-stolen-unc6780-activity</guid><description>Analysis of the TeamPCP supply chain campaign, including the theft of Cisco source code and over 1,000 compromised SaaS environments tracked by Google GTIG as UNC6780.</description><pubDate>Thu, 09 Apr 2026 00:37:07 GMT</pubDate><category>TeamPCP</category><category>UNC6780</category><category>Supply Chain Attack</category><category>Cisco</category><category>Source Code Theft</category><category>Trivy</category><category>ShinyHunters</category><category>SaaS Compromise</category></item><item><title>Wynn Resorts Breach: 21,000 Employees Impacted by ShinyHunters</title><link>https://runtimerebel.com/blog/wynn-resorts-breach-21000-employees-impacted-by-shinyhunters</link><guid isPermaLink="true">https://runtimerebel.com/blog/wynn-resorts-breach-21000-employees-impacted-by-shinyhunters</guid><description>Casino operator Wynn Resorts confirms a data breach affecting 21,000 employees following an extortion attempt by the ShinyHunters threat group.</description><pubDate>Tue, 07 Apr 2026 08:34:56 GMT</pubDate><category>Wynn Resorts</category><category>ShinyHunters</category><category>Employee Data</category><category>PII Exposure</category><category>Extortion</category></item><item><title>TeamPCP Supply Chain Attacks Escalate Amidst Hacker Infighting</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-attacks-escalate-amidst-hacker-infighting</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-attacks-escalate-amidst-hacker-infighting</guid><description>Runtime Rebel details how TeamPCP&apos;s supply chain attacks are leading to breaches, with ShinyHunters and Lapsus$ adding to the chaos.</description><pubDate>Fri, 03 Apr 2026 16:18:40 GMT</pubDate><category>TeamPCP</category><category>ShinyHunters</category><category>Lapsus</category><category>Supply Chain Attack</category><category>Breach</category><category>Threat Actor</category></item><item><title>ShinyHunters Breach: European Commission Cloud Data Theft</title><link>https://runtimerebel.com/blog/shinyhunters-breach-european-commission-cloud-data-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-breach-european-commission-cloud-data-theft</guid><description>ShinyHunters claimed responsibility for a cyber intrusion and 350GB data theft from European Commission cloud systems. Understand the TTPs and mitigation.</description><pubDate>Mon, 30 Mar 2026 12:35:44 GMT</pubDate><category>ShinyHunters</category><category>European Commission</category><category>Data Theft</category><category>Cloud Security</category><category>Cyber Intrusion</category><category>Exfiltration</category></item><item><title>European Commission Confirms Europa.eu Data Breach by ShinyHunters</title><link>https://runtimerebel.com/blog/european-commission-confirms-europa-eu-data-breach-by-shinyhunters</link><guid isPermaLink="true">https://runtimerebel.com/blog/european-commission-confirms-europa-eu-data-breach-by-shinyhunters</guid><description>The European Commission confirms a data breach of the Europa.eu platform after the ShinyHunters group claimed the theft of 1.2 GB of internal database records.</description><pubDate>Mon, 30 Mar 2026 08:41:32 GMT</pubDate><category>ShinyHunters</category><category>European Commission</category><category>Europa Eu</category><category>Data Extortion</category></item><item><title>MITRE ATT&amp;CK Governance and Predator Spyware iOS Evasion Tactics</title><link>https://runtimerebel.com/blog/mitre-att-ck-governance-and-predator-spyware-ios-evasion-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/mitre-att-ck-governance-and-predator-spyware-ios-evasion-tactics</guid><description>Analysis of the new MITRE ATT&amp;CK Advisory Council, Predator spyware bypassing iOS indicators, and Russian cyber-kinetic operation coordination.</description><pubDate>Fri, 27 Feb 2026 16:16:27 GMT</pubDate><category>MITRE ATT CK</category><category>Predator Spyware</category><category>iOS Security</category><category>GRU</category><category>ShinyHunters</category><category>Odido</category></item><item><title>Wynn Resorts Confirms Employee Data Breach Linked to ShinyHunters</title><link>https://runtimerebel.com/blog/wynn-resorts-confirms-employee-data-breach-linked-to-shinyhunters</link><guid isPermaLink="true">https://runtimerebel.com/blog/wynn-resorts-confirms-employee-data-breach-linked-to-shinyhunters</guid><description>Wynn Resorts confirms a data breach affecting employee information after the ShinyHunters group removed stolen records from a dark web leak site.</description><pubDate>Wed, 25 Feb 2026 12:27:36 GMT</pubDate><category>Wynn Resorts</category><category>ShinyHunters</category><category>Data Breach</category><category>BreachForums</category><category>Hospitality Sector</category><category>PII Theft</category></item><item><title>Wynn Resorts Data Breach: ShinyHunters Exfiltrates Employee PII</title><link>https://runtimerebel.com/blog/wynn-resorts-data-breach-shinyhunters-exfiltrates-employee-pii</link><guid isPermaLink="true">https://runtimerebel.com/blog/wynn-resorts-data-breach-shinyhunters-exfiltrates-employee-pii</guid><description>Wynn Resorts confirms a data breach impacting employee PII, attributed to the ShinyHunters extortion gang. Analysis covers TTPs and mitigation strategies.</description><pubDate>Wed, 25 Feb 2026 04:42:06 GMT</pubDate><category>Wynn Resorts</category><category>ShinyHunters</category><category>Data Breach</category><category>Employee Data</category><category>Extortion</category><category>PII</category></item><item><title>ShinyHunters Claims Breach of Odido Telecom Affecting Millions</title><link>https://runtimerebel.com/blog/shinyhunters-claims-breach-of-odido-telecom-affecting-millions</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-claims-breach-of-odido-telecom-affecting-millions</guid><description>The ShinyHunters extortion group claims to have exfiltrated millions of customer records from Dutch telecommunications provider Odido via a third-party breach.</description><pubDate>Tue, 24 Feb 2026 12:22:55 GMT</pubDate><category>ShinyHunters</category><category>Odido</category><category>Telecommunications</category><category>Data Exfiltration</category><category>BreachForums</category></item></channel></rss>