
Loading summary
A
A single stolen token leads to breaches at several major security firms. A new botnet turns abandoned routers into someone else's cyber weapon. A cyber stalker hides behind AI generated fakes. And a ransomware crew builds a whole new arsenal to switch off endpoint defenses. This is Cybersecurity Today and I'm your host David Shipley. Lets get started. Market intelligence platform Clue has confirmed a breach that let attackers steal the OAuth tokens linking it to its customers. Salesforce Environments. The extortion group Icarus has claimed responsibility. Here's how the attack unfolded. Clue says an attacker got in through a compromised legacy credential, one tied to an integration service the company built, prototyped and then abandoned. The credential for that system was also still live. From there, the attacker pivoted into Clu's infrastructure and grabbed the OAuth tokens its customers used to connect Clue to Salesforce. Then came the harvest. Using those stolen tokens, the attacker queried customer Salesforce environments directly. ReliaQuest watched automated Python scripts loop through Salesforce's API. In one case, nearly 1,000 queries in 15 minutes. In another, a six hour extraction window. Bulk CRM theft running quietly from a trusted connection. No password, no MFA prompt, no phished employee. For this one, the attacker had the token. From Salesforce's view, that token is Clue. Access granted, records pulled. The traffic came from infrastructure with no link to Clue's real environment and nobody's alarms went off. The victim list includes cybersecurity firms Huntress Recorded, Future, Tanium, Jamf, as well as other firms like Sprout, Social Gong and Insurity. Most report the same thing. Business contacts, sales records and pricing taken from Salesforce, with platforms and payment systems untouched. Thankfully, Clue has revoked the affected tokens, yanked the old system and credentials that started it and and brought in CrowdStrike as well as notifying law enforcement. Icarus is demanding contact through the session messaging app with the usual threat to leak the data. And if all of this feels oddly familiar, it should. Clue is just the latest hit in a year long run of OAuth token attacks on the Salesforce ecosystem. And the pattern barely changes. Last August, the Crew tracked as UNC6395 stole tokens tied to the Salesloft Drift chatbot and used them to raid More than 700 organizations Salesforce environments including Cloudflare, Google, Palo Alto Networks and Zscaler. Then in November, Shiny Hunters ran that playbook again, this time through Gainsight, reusing secrets stolen in the Drift breach to issue refresh tokens for roughly 285 Salesforce instances. Together, the combined campaigns hit close to 1,000 companies. Nobody broke into Salesforce. They stole the token of a trusted third party app, and Salesforce hands over the data because as far as it can tell, the token is valid. Huntress says Icarus has no known link to Shiny Hunters. It's just a fresh crew running a proven playbook. And that's the worrying part. This technique has now gone mainstream. Right at the moment, non human identities are exploding in popularity thanks to agentic AI. The advice remains the same, although it's much harder now than it was even just a year ago. Lock down your non human identities. That is, assuming you even know which ones exist. A new botnet is turning forgotten routers into hired cyber muscle Researchers at Chianxi's X Lab have documented a previously unknown strain called Airy Stinger. It's compromised more than 4,000 outdated routers and turned them into what the team calls executors, remote controlled nodes that scan proxy tunnel and run commands for the attacker. The clever part in this malware is the architecture. Airy Stinger splits a big scanning job into chunks and farms them out across infected devices in parallel, fast, quiet footprinting that greases the next intrusion. And it doesn't stop there. The malware can rewrite DNS to hijack browsing and silently watch or steal traffic moving through the device. The targets here are all too familiar end of life D link models using flaws that range from one disclosed this year to one from 2013. A nearly 13 year old bug still paying off. Almost half the infections sit in South Korea with China. Second, there's also a Go based variant aimed at NAS devices. Smaller reach, but even more capable. There has been no attribution for Aries Stinger. Yet in xlab's words, many mysteries remain. A New York man is facing federal cyberstalking charges over a ruthless campaign built almost entirely out of fakes. Fake accounts, fabricated quotes and AI generated nude images. 21 year old Anthony Belford was arraigned June 10th after a grand jury indicted him on one count of cyber stalking. None of the allegations have been proven in court. According to authorities, Belford and the victim attended the same college in 2023 and 2024, when the victim transferred to a school in Georgia. Prosecutors say Belford knew and took the campaign there. Between January and March of last year, according to court documents, he created fake profiles across Instagram, LinkedIn, Reddit, X Strava and Yahoo. He allegedly used AI generated nude images of the victim as profile pictures and spread false claims that she'd made racist and anti Muslim remarks. In one case, prosecutors say he used a spoofed email account to send one of those fake images to the victim's own mother. The U.S. attorney's office said it well, cyberstalking, just like physical violence, ruins lives, and victims shouldn't have to suffer in silence. US Federal law now bars sharing or threatening to share intimate images without consent, and that explicitly includes AI generated images and videos. Victims can report to the FBI and flag the FTC if a platform won't pull the content down within 48 hours of a takedown request. The FTC's take it down service exists exactly for this. Canada still hasn't updated its laws to prevent non consensual intimate, deepfaked images and to make them a crime, though it did put its latest attempt on the books before taking the summer off. In March, an Alabama man pled guilty to cyberstalking and extortion after hacking the accounts of hundreds of young women. The same month, an Illinois man pled guilty to breaking into nearly 600 Snapchat accounts to steal private images for trade and sale. While the tools here may be new, the cruelty is not the gentleman. Ransomware as a service crew has built an arsenal aimed at one killing your endpoint defenses before they can fire. Eset says the gang is actively developing a suite of EDR killers led by a custom tool they've named Gentle Killer. It has at least eight variants, each impersonating a legitimate product like Kaspersky or Valorant, and each leaning on bring your own vulnerable driver to reach the kernel and shut protection down. The design is the worrying part. The variants are built so operators can swap out a vulnerable driver or or weaponize a freshly disclosed flaw without having to rewrite the tool. It targets more than 400 processes across roughly 48 security products CrowdStrike, Sentinel One, Microsoft, Sophos, and Eset itself among them. The binaries are packed with commercial protectors and signed with stolen invalid certificates. And they don't just rely on one tool. The kit also folds in EDR killers borrowed from other gangs, but plus a Rust based credential stealer. Eset says the gentleman has an interesting way of picking their targets. They look at their Fortinet Fortigate configuration, which is super bad news following last week's fortableed dump of more than 74,000 Fortigate VPN credentials. Remember, EDRs are an important part of the modern protection stack, but they're not invulnerable and now, all too often, they're the first target on the attacker's list. That's why Defense in Depth, that combines technology controls with human controls is so crucial. And that's Cybersecurity today for Monday, June 22nd. Thanks for listening. I'll be back on the news desk on Wednesday. If you like the show, feel free to drop us a note@technewsday.com or or you can leave a comment under the YouTube video. We also appreciate all of the comments and ratings listeners leave on their favorite podcast sites. Have a great and safe start to your week.
Host: David Shipley
Episode Title: Stolen OAuth Tokens Hit Security Firms, AryStinger Router Botnet Emerges, AI Deepfake Cyberstalking
Date: June 22, 2026
This episode delivers a rapid-fire briefing on the latest cybersecurity threats affecting businesses, including a data breach at security firms via stolen OAuth tokens, the emergence of a new router-based botnet, the rise of AI-driven cyberstalking, and new ransomware tools specifically engineered to disable endpoint defenses. The host, David Shipley, focuses on how techniques are evolving and highlights the urgent need for defense-in-depth strategies.
[00:15 - 05:00]
[06:15 - 08:20]
[08:21 - 11:20]
[11:25 - 14:10]
On OAuth Attack Trends:
On non-human identity management:
On Botnet Fueled by Old Vulnerabilities:
On Deepfake Harassment:
On EDR Targeting:
David Shipley’s June 22 episode draws urgent attention to a surge in sophisticated cyber threats:
A must-listen for CISOs, IT security professionals, and anyone concerned with modern threat actor tactics.