Modalità di lettura

1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack

Some 1.6 million unique email addresses tied to RingCentral have been leaked online, alongside names, physical addresses, and phone numbers, according to Have I Been Pwned. RingCentral disclosed the breach on July 28 and said “it was the target of a sophisticated social engineering campaign” affecting a “limited portion of RingCentral customers.” The comms platform said that it promptly responded to the intrusion upon detecting it, “took steps to stop the unauthorized activity,” and immediately launched an investigation into the security incident with help from a “leading third-party forensic firm.” “We have not seen any new unauthorized activity since taking these remediation efforts,” the company added. RingCentral did not immediately respond to The Register’s request for comment on this story. We will update it as needed. While the company hasn’t named its attacker, notorious data theft and extortion gang ShinyHunters previously claimed it compromised the collaboration platform, according to a post on its data leak site, viewed by The Register. Screenshots of the post also circulated on social media. The crooks claimed they stole more than 623 GB of data, and set a July 30 deadline for RingCentral to pay up - or else the crew would dump the stolen information online. RingCentral apparently didn’t pay the extortion demand, and ShinyHunters followed through on its threat, posting customers’ details on the internet. “The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don’t care,” the crims wrote on August 3. A ShinyHunters spokesperson told us that the group broke into RingCentral by voice-phishing an employee and tricking them into giving the crooks their password. This same group, which security sleuth Dominic Alvieri says is his “top threat group and probably is for most analysts,” has hacked hundreds of organizations since the start of the year, including education tech firms that provide services for schools and universities along with healthcare-sector organizations. Recently, ShinyHunters dumped data stolen from Abbott’s cancer diagnostics business with the leak containing 10.9 million unique email addresses alongside personal and health information. The crooks claim that they made off with more than 30 million rows of customer information, including more than one million Social Security numbers and 7.5 million dates of birth. More concerning, however, they said the haul includes 22 million-plus rows of client notes containing confidential doctor-patient conversations and health information, and more than 20 million medical-order records containing patient IDs, prescription types, order dates, and refill information.® Editor's note: This story was amended post-publication with comment from ShinyHunters.

  •  

Mystery attacker spent a year raiding Salesforce and ServiceNow portals

Someone has spent more than a year rifling through Salesforce and ServiceNow portals around the world, harvesting data that organizations accidentally left open to anyone who came looking. Researchers at Reco have named the operation "City-Forum" after a domain connected to its infrastructure. The domain has pointed to the attacker's server since March 2025, although exactly when the campaign began is unclear. Reco says the activity is continuing and increasing in volume. Reco isn't naming the targets, but said it spotted the attacker poking around portals belonging to telecoms companies, banks and other financial services firms, enterprise software vendors, cybersecurity companies, and public sector bodies. "In the last year, we've seen many threat actors that use Aura enumeration against over-permissioned Salesforce guest users. This actor is different," said Nitay Bachrach, senior security researcher at Reco. On Salesforce, the attacker targets Lightning Web Runtime (LWR) sites through the UI API's GraphQL layer, an approach Reco says it has not found documented in public research or incorporated into publicly available attack tools. Over at ServiceNow, the same operator queries a native Service Portal search endpoint that has received little public attention. The tooling also checks whether Salesforce sites permit self-registration, potentially offering a route from anonymous guest access to an authenticated external account with permission to see considerably more data. Reco said it saw these checks across most of the Salesforce targets it examined. "The threat actor created their own toolset, based on research and techniques which are not well documented online," Bachrach said. "They studied the services to map different common data leak vectors – this is an advanced actor." This isn't casual poking around either. Reco said the busiest Salesforce target logged more than 560,000 events from the attacker's IP during the campaign, almost all attempts to enumerate data available to guest users. Reco linked the Salesforce and ServiceNow activity to the same server, which targeted multiple organizations around the world. More unusually, the attacker hasn't bothered changing its infrastructure: the same IP address and domain have remained in use for at least 17 months, with related custom tooling doing the rounds across both platforms. ServiceNow told us it is "aware of a security company’s blog post claiming certain configurations are creating security risk. As noted in the security company’s post, there are no allegations of a compromise of the ServiceNow environment. Nonetheless, we take third party reports seriously and are investigating accordingly. Our priority is to protect our customers, their data, and our systems." Salesforce has not yet responded to The Register's questions. Salesforce customers have already had one very public lesson in what can happen when guest access gets too generous. In March, ShinyHunters told The Register it had stolen data from around 100 high-profile companies and nearly 400 websites after going after over-permissioned Experience Cloud guest accounts. City-Forum isn't doing quite the same thing, and Reco isn't blaming ShinyHunters. "We don't know who this is, and we're not ruling anyone in or out," Bachrach said. Reco says all the activity it observed was conducted without authentication, with the attacker collecting information that organizations had exposed through permissions, sharing rules, search sources, or other configuration choices. "If the guest can read a record, so can anyone on the internet," Bachrach warned. "That is not a platform vulnerability." Which is good news for Salesforce and ServiceNow, perhaps, but rather less comforting for anyone now wondering what their guest account has been showing the guests. ®

  •  

Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows

Nightmare Eclipse, the serial zero-day hunter who has an axe to grind with Microsoft, published a new Defender zero-day, ShieldBreak, that apparently bypasses Redmond’s RoguePlanet patch (CVE-2026-50656), allowing attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. According to at least one other researcher, the exploit works. “I've tried it, it works on latest Windows 11,” former Microsoft employee and security expert Kevin Beaumont said. Beaumont also published three detections and hunting queries for ShieldBreak to help defenders rapidly find any stealthy threats. So until Microsoft fixes this latest zero-day, we’d highly suggest using these queries. ShieldBreak is the 10th zero-day from Nightmare Eclipse since they began their scorched-earth strategy against Microsoft in early April. The prolific bug finder and exploit developer is suspected to be a former, very disgruntled, Microsoft employee. And in typical fashion, this latest zero-day drop occurred just hours after Redmond’s monthly Patch Tuesday that fixed 421 security problems in its products - but ShieldBreak isn't one of them. It’s a local privilege-escalation exploit that, according to Nightmare, allows attackers to gain SYSTEM-level privileges. “The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate. Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well,” they said. While Nightmare claims that the new exploit is a patch bypass for the earlier RoguePlanet vulnerability, CVE-2026-50656, which Microsoft quietly fixed in July, Beaumont pointed out that the two flaws operate very differently. “RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files,” he posted. “ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API).” A Microsoft spokesperson told us the company "is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims." The spokesperson added: "Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible. Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public." This latest zero-day comes a month after Nightmare Eclipse published its previous vulnerability along with partial exploit code. Nightmare’s July drop, called LegacyHive, is a local privilege escalation flaw that targets Windows’ user hives - the section of the Windows Registry that stores a user's specific desktop settings, application preferences, and environment configurations. It's patched with CVE-2026-62832. There's also a June zero-day called GreatXML that Nightmare developed. The researcher claims the flaw allows a local attacker with administrator rights to bypass BitLocker encryption by manipulating the Windows Recovery Environment. But it has been patched with CVE-2026-50661. The prolific zero-day hunter’s earlier seven Windows bugs do have patches. These include BlueHammer (CVE-2026-33825), RedSun (CVE-2026-41091), UnDefend (CVE-2026-45498), YellowKey (CVE-2026-45585), GreenPlasma (CVE-2026-45586), MiniPlasma (CVE-2020-17103), and RoguePlanet (CVE-2026-50656). After threatening legal action against Nightmare Eclipse in May, and then facing rapid backlash from just about every other security researcher on the planet, Microsoft walked back its talk of siccing its Digital Crimes Unit on people who don’t follow its vulnerability disclosure rules.® Correction: There are patches for GreatXML and Legacy Hive.

  •  

Tutti pazzi per il crime

Se a Garlasco, in provincia di Pavia, ci fosse stata Jessica Fletcher, il caso dell’omicidio di Chiara Poggi sarebbe stato già risolto. Capacità di osservazione, intuizione e una buona dose di fortuna nella fiction, cinematografica, televisiva o letteraria che sia, sono sufficienti per trovare l’assassino – e infatti la “signora in giallo” non sbagliava mai-. Nella realtà, non va così. Nonostante i più sofisticati strumenti di analisi, tracce di Dna, impronte, macchie di sangue trascurate e poi magicamente ritrovate, hanno come unico risultato quello di alimentare il dubbio.

Si crea così il giallo perfetto, quello che non ha mai fine e che ci fa diventare tutti detective. La passione per il crime è tale che i programmi televisivi si moltiplicano, dalla mattina alla sera, senza saltare il pomeriggio, con dati di ascolto notevoli, e nascono canali dedicati esclusivamente a serie, film, fiction su casi inventati o realmente accaduti. Anche fra i libri, quelli che tengono meglio nelle classifiche delle vendite sono spesso dei gialli.

Emozioni da poco

Ma perché il crime ci attira così tanto? «La letteratura scientifica ci dice che il racconto di storie che si sviluppano intorno a un delitto svolgono la stessa funzione delle fiabe per i bambini. L’imprevedibilità che le caratterizza dà forma alle nostre paure e incertezze, e in qualche modo ci rassicura. Sono fatti terribili che potrebbero capitarci, ma sapere che il colpevole sarà assicurato alla giustizia ci tranquillizza e procura una sensazione positiva: dopo il caos torna la calma» spiega la presidente nazionale dell’Ordine degli psicologi, Maria Antonietta Gulino. Così come accade ai bambini che chiedono sempre la stessa novella, anche noi seguiamo queste storie gialle, appassionandoci.

Il giornalista e narratore di storie, in tv, in rete e a teatro, Stefano Nazzi, la spiega così: «Suscitano più attenzione, anche da parte dei media, quelle storie che ci appaiono più simili alle nostre, che coinvolgono famiglie come le nostre, che potrebbero accadere ai nostri figli», in sintesi ci immedesimiamo, senza fortunatamente fare la stessa fine.

Secondo Marco Vichi, che ha scritto quindici libri a tema poliziesco con protagonista l’umanissimo commissario Bordelli (ma non si definisce un giallista), non è un fenomeno che nasce oggi: «Non credo sia una questione attuale, è sempre successo: i crimini più vicini a noi incuriosiscono, perché si parla di persone, mentre le guerre ce le raccontano con i numeri e le sentiamo lontane, anche se proprio lontane fisicamente non sono» spiega.

Ritorno a Garlasco

Torniamo al caso Garlasco, e più precisamente al 13 agosto 2007. Francesco Selvi, allora inviato del telegiornale di La7 – aveva seguito anche altri casi di cronaca come Cogne e quello di Omar ed Erika -, era lì quel giorno. «Una giornata calda e umida, tipica della Pianura Padana, quasi soffocante. Il caso aveva tutte le caratteristiche del giallo estivo: una ragazza di una famiglia benestante, uccisa in piena estate nella villetta dei genitori, in un paese della provincia lombarda, conosciuto per le sue discoteche e piscine, frequentate anche da Ron, che a Garlasco abita, e dall’amico Lucio Dalla. Noi giornalisti stazionavamo fuori dal giardino, in attesa di qualche notizia. La prima ipotesi a circolare fu quella di una rapina finita male, ma venne esclusa subito perché non era stato rubato niente» ricorda quasi vent’anni dopo.

Vent’anni di servizi giornalistici e trasmissioni televisive, il fidanzato, Alberto Stasi, condannato per omicidio e poi la riapertura delle indagini con un nuovo mostro da inseguire con le telecamere, Andrea Sempio. «A quel tempo – prosegue Selvi – non pensavamo che questa vicenda sarebbe durata così a lungo: il fatto che Chiara Poggi quella mattina avesse aperto la porta al suo assassino fece svoltare le indagini nell’ambito familiare e dei legami sentimentali, la strada che più spesso porta alla verità».

Il caravanserraglio televisivo funziona «quando si smette di attenersi ai fatti e si lascia spazio alle ipotesi più fantasiose: come succede sui social, ognuno dice la sua e ha il proprio killer immaginario, si mettono in mezzo le cugine, il fratello di Chiara, la famiglia che nasconde qualcosa, i riti nel vicino santuario» afferma Nazzi. Il fallo di confusione direbbe qualcuno, ma a chi giova questo can can? Alle emittenti televisive, agli sponsor disposti a pagare a peso d’oro uno spazio pubblicitario, agli ospiti dei talk che acquistano una fama utile alle loro carriere.

La mancanza di rispetto nei confronti delle vittime e dei familiari è evidente, ma nessuno sembra preoccuparsene: «C’è una rincorsa ossessiva alle notizie da parte dei media, come se non esistesse più nessun tipo di confine, questo è evidente anche nel caso Garlasco, ma succede quasi sempre» precisa Nazzi. Su questo concorda anche Vichi, che non ama pronunciarsi sui fatti di attualità: «Tengo sempre lontana la cronaca, non ho opinioni determinanti sui casi reali, lascio fare ai giudici, ma devo dire che questo baraccone mediatico su Garlasco è offensivo per la vittima e per i suoi familiari e proprio non mi piace».

Il truce che piace

L’atteggiamento quasi morboso del giornalismo nei confronti di fatti di cronaca non è però prerogativa esclusiva dei nostri tempi. Il 17 agosto 1924, all’indomani del ritrovamento del corpo di Giacomo Matteotti, il “Corriere della sera” intitolava: «Gli emozionanti particolari della lugubre scoperta. Lo stato delle misere spoglie». Nell’articolo ci si dilungava sullo stato del cadavere abbandonato in una macchia di cerri dove l’aveva ritrovato il cane di un giovane brigadiere dei Carabinieri uscito per stanare volpi. Raccontava al giornalista: «Ho visto biancheggiare due oggetti che mi sembravano delle ossa umane. Mi sono avvicinato e le ho esaminate attentamente. Si trattava di una scapola e di un femore con qualche brandello di carne ancora attaccata». Un racconto da far invidia ai più truci serial americani che proprio sulle autopsie di cadaveri basano il loro successo, come Bones, Ncis, Csi.E la valenza politica dell’assassinio sacrificata – forse intenzionalmente, visto che era stato ucciso più di due mesi prima da una squadra fascista – a vantaggio della morbosità dei lettori.

Nero toscano

Al destino di una descrizione impietosa non sfuggirono neppure le vittime del Mostro di Firenze. I dettagli dei corpi spogliati e mutilati finirono nei servizi dei giornali dell’epoca. Il più grande mistero della cronaca italiana – come lo definiscono molti – a distanza di 40 anni dall’ultimo delitto fa ancora il pieno di ascolti quando i media lo ripropongono: «L’uccisione di 16 giovani da parte del serial killer più famoso della storia del nostro Paese continua a colpire l’attenzione delle persone, certamente perché un “colpevole” convincente non è mai stato trovato e per questo motivo sono state fatte le ipotesi più disparate» prosegue Nazi. I compagni di merende, la pista sarda, le messe nere, la massoneria deviata, in quasi sessant’anni si è detto di tutto di più. Ma non è ancora stata scritta la parola fine.

Il gioco è finito

La continua esposizione ad argomenti e immagini scabrosi può innescare in persone particolarmente sensibili e in situazione di stress due diversi processi: da un lato l’indifferenza anche di fronte ai fatti più gravi, come l’uccisione di un bambino, in una sorta di scollamento dalla realtà. Dall’altra, quando il colpevole con funzione catartica non si trova, l’effetto rassicurante della fiaba può venir meno. «Se la paura diventa fobia e il piacere si trasforma in ossessione, allora bisogna intervenire – conclude la psicologa -. Può anche innescarsi un corto circuito per cui i fatti visti in tv si sovrappongono alla realtà, e l’ansia invece di placarsi aumenta e si autoalimenta. In quel caso bisogna chiedere aiuto». Il gioco “a fare il detective” è finito.

Il giallo che fa scuola

Fra le serie tv poliziesche storiche, oltre a La signora in giallo, che dove va lei c’è un omicidio, merita una menzione Il tenente Colombo, umanissimo nel suo impermeabile chiaro sempre spiegazzato. Ma la serie considerata più longeva è Law & Order – I due volti della giustizia. Prodotta dal1990 al 2010 e poi ripresa dal 2022 ad oggi, è ambientata a New York: piace perché mette insieme il crime con il legal thriller, cioè poliziotti contro delinquenti e procuratori contro avvocati. Da essa sono nati numerosi spin off, anch’essi di notevole successo. Come La signora in giallo ha una sigla musicale inconfondibile.

Luce

E una volta che i responsabili dei delitti sono scoperti, cosa succede? Marco Vichi, insieme a Valerio Aiolli, Enzo Fileno Carabba, Leonardo Gori, Emiliano Gucci con Luce (Leonardo Libri) racconta la vita nel carcere, attraverso storie di sofferenza, rabbia, rassegnazione e speranza, rendendo visibile l’invisibile, cioè il mondo nella prigione.

L'articolo Tutti pazzi per il crime proviene da Informatore.

  •  
❌