<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:-:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aciscounified_communications_manager-/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 18 Jun 2026 15:45:22 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aciscounified_communications_manager-/feed.xml" rel="self" type="application/rss+xml"/><item><title>ShinyHunters Ransomware Group Claims icsecurity.com Victim, Exfiltrates 2.7M Records</title><link>https://feed.craftedsignal.io/briefs/2026-06-shinyhunters-icsecurity/</link><pubDate>Thu, 18 Jun 2026 15:45:22 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-06-shinyhunters-icsecurity/</guid><description>The financially motivated ShinyHunters ransomware group, operating its shinysp1d3r RaaS, has claimed icsecurity.com as a new victim, compromising over 2.7 million records via credential stuffing and exploitation of cloud services like Snowflake, with the intent to extort through data leakage.</description><content:encoded><![CDATA[<p>The ShinyHunters ransomware group, a financially motivated data-theft and extortion entity active since 2020, has claimed icsecurity.com as a recent victim. This group, known for high-profile breaches including Ticketmaster via Snowflake, launched its Ransomware-as-a-Service (RaaS) offering, &quot;shinysp1d3r,&quot; in 2025. For the icsecurity.com incident, ShinyHunters claims to have compromised over 2.7 million records and other internal corporate data, threatening public data leakage by June 22, 2026, if ransom demands are not met. The group leverages techniques such as credential stuffing against cloud platforms like Snowflake, and exploits vulnerabilities including CVE-2025-61882 in Oracle E-Business Suite and CVE-2026-20045 in Cisco Unified Communications to gain initial access and exfiltrate sensitive data for extortion purposes. They primarily target organizations across technology, consumer services, financial services, and education sectors, with a significant focus on US-based entities.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li><strong>Initial Access via Credential Stuffing</strong>: ShinyHunters obtains valid credentials (often from prior breaches or infostealer data) and attempts to log into target cloud services (e.g., Snowflake, Salesforce, or other SaaS applications) that may lack robust multi-factor authentication, gaining initial unauthorized access.</li>
<li><strong>Exploitation of Vulnerabilities</strong>: Attackers may exploit known vulnerabilities, such as CVE-2025-61882 in Oracle E-Business Suite or CVE-2026-20045 in Cisco Unified Communications, to achieve privileged access, establish persistence, or further compromise network infrastructure.</li>
<li><strong>Lateral Movement and Credential Access</strong>: Once inside, the group leverages alternate authentication material (e.g., application access tokens) and unsecured credentials to move laterally within cloud environments or connected systems, expanding their footprint and access to sensitive data sources.</li>
<li><strong>Data Collection from Repositories</strong>: ShinyHunters identifies and aggregates sensitive data from various information repositories, including cloud databases (e.g., Google BigQuery), cloud storage, and customer relationship management (CRM) systems (e.g., Salesforce), focusing on PII, financial information, and corporate intellectual property.</li>
<li><strong>Data Exfiltration Over Web Service</strong>: The aggregated data is exfiltrated from the compromised environment, typically disguised as legitimate traffic over web services, to attacker-controlled infrastructure, often hosted on dark web (.onion) domains.</li>
<li><strong>Extortion and Data Leakage</strong>: Following successful data exfiltration, the group issues a ransom demand, threatening to publicly leak the stolen data on their dark web data leak sites if the victim fails to pay by a specified deadline, as seen with icsecurity.com.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The compromise of icsecurity.com resulted in the theft of over 2.7 million records and other internal corporate data from a US-based technology company. ShinyHunters has a history of targeting 128 victims globally, primarily in the US (94 victims), across sectors including technology (22 victims), consumer services, financial services, and education. If the extortion demands are not met, the group typically publishes the stolen data on its dedicated dark web data leak sites, leading to significant reputational damage, regulatory fines, competitive disadvantage, and potential legal action from affected individuals whose PII has been exposed.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Deploy the Sigma rules in this brief to your SIEM and tune for your environment to detect suspicious login attempts and C2 communications.</li>
<li>Implement multi-factor authentication (MFA) for all user accounts, especially for cloud services like Snowflake and Salesforce, to mitigate credential stuffing attacks.</li>
<li>Patch CVE-2025-61882 on all Oracle E-Business Suite (EBS) installations immediately.</li>
<li>Patch CVE-2026-20045 on all Cisco Unified Communications systems immediately.</li>
<li>Enable comprehensive logging for web servers, DNS queries, and network connections to allow for detection of suspicious activity like credential stuffing and C2 communication.</li>
<li>Block the C2 domains and URLs listed in the IOC table at your network perimeter, DNS resolver, and proxy servers.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>ransomware</category><category>data-theft</category><category>extortion</category><category>cloud-security</category><category>threat-actor-group</category><category>credential-stuffing</category></item></channel></rss>