Cyber Cookie mascotCyber Cookie
Menu ▾
← LatestIssue #65August 15, 2026

ShinyHunters Leaks 1.6 Million RingCentral Accounts

ShinyHunters has dumped 280GB of stolen data from RingCentral after the company refused to pay up, exposing personal details on 1.6 million accounts. Mac users running Screen Sharing should patch immediately — attackers are actively exploiting an authentication bypass to hijack machines and mine cryptocurrency. Check whether your Apple device is up to date, and disable Screen Sharing if you don't use it.

Breach of the Day

RingCentral Hit by ShinyHunters — 1.6 Million Accounts Exposed

RingCentral, a cloud-based business communications platform used by over 600,000 companies for calls, messaging, and voicemail, confirmed a breach after the ShinyHunters extortion group claimed responsibility and made good on their threat, according to Bleeping Computer.

The attackers got in through a social engineering campaign (manipulating people rather than breaking code — tricking employees into handing over access). From there, ShinyHunters claimed to have pulled 623GB of data. When RingCentral refused to pay a ransom to have it destroyed, the group published 280GB of that data on a dark web leak site.

Have I Been Pwned, the free breach-notification database, analysed the leaked files and confirmed records for 1.6 million accounts — including names, email addresses, phone numbers, and physical addresses.

ShinyHunters is not new to this. The group has been linked to breaches at dozens of Snowflake customers, Salesforce-connected platforms, and recently, organisations hit through an Oracle PeopleSoft zero-day (a previously unknown flaw with no available fix at the time of exploitation). The pattern is consistent: target a third-party integration, steal at scale, demand payment, publish when refused.

RingCentral says the core platform was not disrupted and that affected customers are being contacted directly.

What you should do: Visit Have I Been Pwned and search your email address to find out whether your data appeared in this or any other known breach. If you use RingCentral, watch for phishing emails using your personal details — attackers now know your name, email, and phone number.

Emerging Threats

Attackers Are Hijacking Macs Through Screen Sharing — and Mining Crypto With Them

Apple's macOS Screen Sharing is a built-in remote desktop feature that lets someone control your Mac over a network. It turns out it had a serious authentication bypass flaw — CVE-2026-65400 — meaning an attacker could connect to your machine remotely without needing a valid password, according to Bleeping Computer.

The Netherlands' National Cyber Security Centre confirmed active exploitation in the wild. In every reported case, attackers gained root access (full administrative control over the system) and quietly installed a Monero cryptocurrency miner, using the victim's hardware to generate money for the attacker.

Apple patched this flaw on August 6 in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. If your Mac isn't on one of those versions, it is exposed.

What you should do: Open System Settings, check your macOS version, and update immediately. If you can't update right now, go to General → Sharing → Screen Sharing and turn it off.

Vulnerability Watch

CVE ID not confirmed in source — check the original advisory before acting.

What Evooo1Bot targets: Home routers, enterprise networking equipment, and IoT (Internet of Things — everyday devices connected to the internet, like smart routers and remote-terminal units) running Linux-based firmware.

What it is: Evooo1Bot is a new botnet — a network of hijacked devices secretly controlled by an attacker — built on leaked source code from the notorious Mirai malware. Researchers at Fortinet's FortiGuard Labs identified it after seeing coordinated attacks on edge devices across multiple regions since July 2026, as reported by Infosecurity Magazine.

Who's at risk: Anyone running an unpatched router or internet-connected device from brands including D-Link, NETGEAR, Tenda, and Telesquare, particularly where the device's admin interface is exposed directly to the internet.

CVSS: Not yet scored for the botnet itself — treat as High until confirmed.

Root cause: The botnet exploits known, unpatched vulnerabilities in edge devices — some dating back to 2007. Manufacturers issued fixes, but many devices in the field were never updated, leaving attackers with a large pool of targets to automate against.

Attack vector: Evooo1Bot scans the internet for vulnerable devices, fires exploit payloads at them, and once inside, installs a persistent agent. That agent connects back to attacker-controlled infrastructure and — most significantly — activates a SOCKS relay module that turns the compromised device into a proxy, concealing the attacker's real location while routing further attacks through the victim's network.

Recommended actions:

  1. Log into your router's admin panel and apply any available firmware updates immediately.
  2. Disable remote management interfaces unless you specifically need them — check your router settings for "Remote Access" or "WAN Management" and turn them off.
  3. If your router model appears in the article (D-Link, NETGEAR, Tenda, Telesquare), check the manufacturer's support page for a patch or end-of-life notice.
Defender's Corner

Turn Off Screen Sharing If You Don't Use It

The macOS Screen Sharing vulnerability being actively exploited right now is a good reminder that built-in remote access features are a liability when left on by default. Screen Sharing, Apple's remote desktop tool, only needs to be reachable from the internet to become a target — and many users have no idea it's enabled.

Disabling it takes thirty seconds. On your Mac, open System Settings → General → Sharing, find Screen Sharing, and switch it off. If you do need remote access to your Mac, consider using it only over a VPN rather than exposing port 5900 directly to the internet.

More broadly, go through everything listed under Sharing in System Settings. Remote Login, Remote Management, and AirPlay Receiver are all features worth disabling if you don't actively use them.

Compliance Pulse

France's Tax Authority Confirms Breach of Up to 600,000 Citizens' Records

France's Directorate General of Public Finances (DGFiP) confirmed that an attacker accessed its internal systems in late June after stealing or misusing an employee's identity, according to The Record. A hacker using the alias ZeroBytes claims to have extracted data on over 600,000 people, including tax identification numbers, family details, and financial status — the kind of data that enables highly targeted fraud. French authorities have opened a criminal complaint and will notify affected individuals. It is the latest in a string of French government breaches this year.

Patch Tuesday came early this year, and August apparently didn't get the memo.

Cyber Cookie is AI-assisted. Always verify critical information with official sources before acting.