{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/cisco-unified-communications/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":["ShinyHunters"],"_cs_cpes":["cpe:2.3:a:oracle:concurrent_processing:*:*:*:*:*:*:*:*","cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:-:*:*:*","cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:session_management:*:*:*","cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:*:*:*:*:*:*:*:*","cpe:2.3:a:cisco:unity_connection:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2025-61882"},{"cvss":8.2,"id":"CVE-2026-20045"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Oracle E-Business Suite (EBS)","Cisco Unified Communications","Snowflake","Salesforce","Google BigQuery","Anodot","Oracle E-Business Suite (\u003c= 2025-10-01)"],"_cs_severities":["high"],"_cs_tags":["ransomware","data-theft","extortion","cloud-security","threat-actor-group","credential-stuffing"],"_cs_type":"threat","_cs_vendors":["Oracle","Cisco","Snowflake Inc.","Salesforce","Google","Anodot"],"content_html":"\u003cp\u003eThe ShinyHunters ransomware group, a financially motivated data-theft and extortion entity active since 2020, has claimed icsecurity.com as a recent victim. This group, known for high-profile breaches including Ticketmaster via Snowflake, launched its Ransomware-as-a-Service (RaaS) offering, \u0026quot;shinysp1d3r,\u0026quot; in 2025. For the icsecurity.com incident, ShinyHunters claims to have compromised over 2.7 million records and other internal corporate data, threatening public data leakage by June 22, 2026, if ransom demands are not met. The group leverages techniques such as credential stuffing against cloud platforms like Snowflake, and exploits vulnerabilities including CVE-2025-61882 in Oracle E-Business Suite and CVE-2026-20045 in Cisco Unified Communications to gain initial access and exfiltrate sensitive data for extortion purposes. They primarily target organizations across technology, consumer services, financial services, and education sectors, with a significant focus on US-based entities.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Access via Credential Stuffing\u003c/strong\u003e: ShinyHunters obtains valid credentials (often from prior breaches or infostealer data) and attempts to log into target cloud services (e.g., Snowflake, Salesforce, or other SaaS applications) that may lack robust multi-factor authentication, gaining initial unauthorized access.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eExploitation of Vulnerabilities\u003c/strong\u003e: Attackers may exploit known vulnerabilities, such as CVE-2025-61882 in Oracle E-Business Suite or CVE-2026-20045 in Cisco Unified Communications, to achieve privileged access, establish persistence, or further compromise network infrastructure.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eLateral Movement and Credential Access\u003c/strong\u003e: Once inside, the group leverages alternate authentication material (e.g., application access tokens) and unsecured credentials to move laterally within cloud environments or connected systems, expanding their footprint and access to sensitive data sources.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eData Collection from Repositories\u003c/strong\u003e: ShinyHunters identifies and aggregates sensitive data from various information repositories, including cloud databases (e.g., Google BigQuery), cloud storage, and customer relationship management (CRM) systems (e.g., Salesforce), focusing on PII, financial information, and corporate intellectual property.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eData Exfiltration Over Web Service\u003c/strong\u003e: The aggregated data is exfiltrated from the compromised environment, typically disguised as legitimate traffic over web services, to attacker-controlled infrastructure, often hosted on dark web (.onion) domains.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eExtortion and Data Leakage\u003c/strong\u003e: Following successful data exfiltration, the group issues a ransom demand, threatening to publicly leak the stolen data on their dark web data leak sites if the victim fails to pay by a specified deadline, as seen with icsecurity.com.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe compromise of icsecurity.com resulted in the theft of over 2.7 million records and other internal corporate data from a US-based technology company. ShinyHunters has a history of targeting 128 victims globally, primarily in the US (94 victims), across sectors including technology (22 victims), consumer services, financial services, and education. If the extortion demands are not met, the group typically publishes the stolen data on its dedicated dark web data leak sites, leading to significant reputational damage, regulatory fines, competitive disadvantage, and potential legal action from affected individuals whose PII has been exposed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the Sigma rules in this brief to your SIEM and tune for your environment to detect suspicious login attempts and C2 communications.\u003c/li\u003e\n\u003cli\u003eImplement multi-factor authentication (MFA) for all user accounts, especially for cloud services like Snowflake and Salesforce, to mitigate credential stuffing attacks.\u003c/li\u003e\n\u003cli\u003ePatch CVE-2025-61882 on all Oracle E-Business Suite (EBS) installations immediately.\u003c/li\u003e\n\u003cli\u003ePatch CVE-2026-20045 on all Cisco Unified Communications systems immediately.\u003c/li\u003e\n\u003cli\u003eEnable comprehensive logging for web servers, DNS queries, and network connections to allow for detection of suspicious activity like credential stuffing and C2 communication.\u003c/li\u003e\n\u003cli\u003eBlock the C2 domains and URLs listed in the IOC table at your network perimeter, DNS resolver, and proxy servers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-21T11:13:31Z","date_published":"2026-06-18T15:45:22Z","id":"https://feed.craftedsignal.io/briefs/2026-06-shinyhunters-icsecurity/","summary":"The financially motivated ShinyHunters ransomware group, operating its shinysp1d3r RaaS, has claimed icsecurity.com as a new victim, compromising over 2.7 million records via credential stuffing and exploitation of cloud services like Snowflake, with the intent to extort through data leakage.","title":"ShinyHunters Ransomware Group Claims icsecurity.com Victim, Exfiltrates 2.7M Records","url":"https://feed.craftedsignal.io/briefs/2026-06-shinyhunters-icsecurity/"}],"language":"en","title":"CraftedSignal Threat Feed - Cisco Unified Communications","version":"https://jsonfeed.org/version/1.1"}