
Uncloaked: A Weaponized Detection Tool, a Government Contact Leak, and Another Vendor Breach
Three stories from the past couple of weeks, none of them a traditional hack. A misconfigured platform, a security tool turned against the people it was built to help, and a breach that arrived through a vendor nobody was thinking about.
1. A data-extortion group is running a campaign against misconfigured Microsoft Power Pages
A previously unknown group calling itself ExfilSquad claimed on July 26 to have exfiltrated data from roughly 15 organisations, city governments, universities, a major public school system, and private companies, and began demanding payment. Security researchers have since backed up the claims after the group released samples. The likely cause, according to a follow-up report: misconfiguration of Microsoft Power Page portals.
One confirmed victim is PNLD, a database used by UK police and government bodies, where names, organisations, and work email addresses of police officers, criminal justice staff, and government partners were exposed. The National Crime Agency and the Information Commissioner's Office are both involved in the investigation.
Why it matters: the exposed data here is "just" contact information, no financial data, no passwords, which makes it easy to underrate. But names, roles, and work emails for police and government staff are exactly the raw material for targeted phishing and social engineering campaigns, the leak itself doesn't need to be catastrophic to enable something that is.
2. A misconfiguration-detection tool got weaponized against the misconfiguration it was built to find
This is the one worth sitting with. ShinyHunters ran what's been called the Salesforce Aura Campaign against an estimated 300 to 400 organisations, exploiting misconfigured Salesforce Experience Cloud guest user profiles via the /s/sfsites/aura API endpoint. The tool used to find and exploit these misconfigurations was a weaponized version of AuraInspector, an open-source tool Mandiant released in January 2026 specifically to help administrators detect this exact class of Salesforce misconfiguration.
Why it matters: a defensive tool built to help organisations find their own exposure got repurposed as the attack tool against the same exposure, at scale, within months of its release. It's a sharp illustration of a pattern worth remembering: publishing a detection method educates defenders and attackers simultaneously, and the gap between "here's how to check yourself" and "here's how to exploit it" can be small enough that a tool's second life happens fast.
3. A hardware wallet company got breached through its shipping provider
Trezor, which makes hardware wallets specifically to protect cryptocurrency from exactly this kind of compromise, disclosed a breach affecting nearly 14,000 customers across the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. The cause wasn't Trezor's own systems, it was ShipMonk, their shipping and logistics provider, which was hacked, exposing customer names, shipping addresses, emails, and phone numbers for anyone who'd ordered between May and August 2026.
Why it matters: Trezor's own security posture is arguably beside the point here. A company can do everything right internally and still be breached through a vendor holding a much narrower slice of customer data for a much more mundane reason, shipping labels. Third-party risk doesn't require the vendor to be careless in some dramatic way, just present in your data flow and less scrutinised than you'd apply to your own systems.
What connects all three
None of these needed sophisticated intrusion techniques. A platform's guest-access defaults, a detection tool published for good reasons and repurposed for bad ones, a shipping vendor several steps removed from the actual product. Misconfiguration and vendor exposure keep outpacing traditional exploitation as the actual cause behind headline breaches, and none of the three above would have needed anything more advanced than someone checking before it mattered.
Sources: Cybersecurity Dive on the ExfilSquad campaign · Rescana on the PNLD breach · Wikipedia on the Salesforce Aura Campaign · Privacy Guides on the Trezor/ShipMonk breach
Decloak checks for exactly this class of platform and API misconfiguration automatically, alongside seven other attack surfaces, in a free 15-second scan. Scan your site free →