惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
美团技术团队
Recent Announcements
Recent Announcements
B
Blog
GbyAI
GbyAI
雷峰网
雷峰网
博客园_首页
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
T
Tailwind CSS Blog
M
MIT News - Artificial intelligence
V
V2EX
人人都是产品经理
人人都是产品经理
爱范儿
爱范儿
L
LangChain Blog
Microsoft Security Blog
Microsoft Security Blog
宝玉的分享
宝玉的分享
A
About on SuperTechFans
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
U
Unit 42
Hugging Face - Blog
Hugging Face - Blog
F
Fortinet All Blogs
N
Netflix TechBlog - Medium
Last Week in AI
Last Week in AI
aimingoo的专栏
aimingoo的专栏

Troy Hunt's Blog

Weekly Update 521: Breach Perception v. Reality Weekly Update 520: The Unscripted Edition Weekly Update 519: Breaches & Data Integrity A Cautionary Tale About Data Breach Claims, Verification and Carhartt Weekly Update 518: IoT Doorlock Nirvana with UniFi Welcoming the Sri Lankan Government to Have I Been Pwned Weekly Update 517: Cyber Ransoms Weekly Update 516: Live From Vietnam Welcoming the Nepalese Government to Have I Been Pwned Weekly Update 515 Weekly Update 514: This Week in Data Breaches Weekly Update 513: Clauding The Home Network Weekly Update 512: IoT Lockout Fail Weekly Update 511: Live from my Riad in Marrakech Swimming Pools, Pee, and Trying to Delete Your Data From the Internet Weekly Update 510: Live From Mallorca with Scott Helme Weekly Update 509 Weekly Update 508 Weekly Update 507 Welcoming the Philippine Government to Have I Been Pwned 1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever Weekly Update 506 Welcoming the Bhutanese Government to Have I Been Pwned Weekly Update 505 Weekly Update 504 Welcoming the Bahamian Government to Have I Been Pwned Welcoming the Bangladesh Government to Have I Been Pwned Welcoming the Costa Rican Government to Have I Been Pwned Weekly Update 503 Weekly Update 501
Weekly Update 502
Troy Hunt · 2026-05-06 · via Troy Hunt's Blog

It's a fascinating display of leverage: the ShinyHunters folks, with very limited resources and experience (their demographic will be teenagers to their early 20s), consistently gaining access to the data of massive brands. Not through technical ingenuity alone (although I'm sure there's a portion of that), but primarily through good ol' social engineering. That's coming through in the disclosure notices from the impacted companies, and Mandiant has a good write-up of it too:

These operations primarily leverage sophisticated voice phishing (vishing) and victim-branded credential harvesting sites to gain initial access to corporate environments by obtaining single sign-on (SSO) credentials and multi-factor authentication (MFA) codes

Question now is how long their run will go for. There's a very predictable ending if things keep going in this direction but right now, they show little sign of abating.

Listen on Apple Podcasts

Watch and Listen on YouTube

Download via RSS

Weekly update