Shinyhunters used stolen Claude access to control home EV chargers in attack on 200 organizations
ns123abc · x · 2026-09-11
- A French Shinyhunters affiliate mass-downloaded 1.8 million Android apps from Google Play, scraped every one for hardcoded API keys, and dumped the credentials into Telegram groups.
- Separately, Shinyhunters used stolen Claude access belonging to an EV charger company to remotely control charging current in customers' homes as part of a supply chain attack involving 200 organizations.
More from Safety
- 6TB leak from a Chinese LLM router exposes credentials to hijack Xiaomi, Huawei and gov entities — teortaxesTex · 2026-09-11
- Epoch AI data: China's top models trail US frontier by 6.3 months, real gap closer to 8 — deanwball · 2026-09-11
- Biorisk defense is man-made, not natural difficulty: the open-model bioweapon debate continues — JMannhart · 2026-09-11
- Open-source models by 2029 could make bioweapon creation "almost trivial", debaters clash on biorisk — JMannhart · 2026-09-11
- DeepSeek and Moonshot accused of secretly relaying user prompts to Claude via fake accounts — burny_tech · 2026-09-11
- Leo Laporte: AI-created worms are malware, not doom — prosecute the creators — GaryMarcus · 2026-09-11