ShinyHunters FBI Breach, PeopleSoft Attack Surge, Bitget Loses Millions
Quick Answer
The latest cybersecurity news covers the ShinyHunters FBI breach claim, Bitget’s $388 million crypto theft, exploited Citrix zero-days, AI-driven attacks, ransomware, malware campaigns, and critical vulnerabilities affecting enterprise, cloud, WordPress, and mobile systems.
Last week was packed with high-impact cyber incidents. A notorious extortion gang claimed it had broken into the FBI, and North Korea-linked hackers were suspected of draining a major crypto exchange. Attackers exploited two Citrix zero-days at global scale, while AI agents showed up in an alarming number of attacks and accidents. Here is a quick roundup of the biggest developments.
Strong SPF, DKIM, and DMARC configurations are an important part of email security. These protocols help organizations authenticate legitimate emails, detect unauthorized sending activity, and reduce the risk of domain spoofing and email-based phishing attacks.
ShinyHunters claims it hacked the FBI!
The ShinyHunters extortion group says it compromised the FBI and defaced the bureau’s job application portal. It claims to have stolen around 2 TB of data covering agents and job applicants, and says it got in through a previously unknown flaw in Oracle PeopleSoft. The FBI says it is aware of the claims and is investigating.
The group sent reporters a sample that appeared to hold personal details of nearly 5,000 FBI employees, including home addresses, phone numbers and family members. The bureau says it does not yet know whether the entry point was its own systems or a third-party provider. The hackers are also demanding that the FBI retract a public warning about their tactics within a week. Source: Nextgov/FCW
Oracle PeopleSoft hit by a fresh wave of attacks!
Google warns that ShinyHunters-linked hackers, tracked as UNC6240, have renewed mass exploitation of a critical PeopleSoft flaw (CVE-2026-35273, CVSS 9.8). They modified their exploit to slip past web application firewall rules that organizations had put in place after the first wave.
Mandiant said earlier this year that it had notified more than 100 organizations, mostly in the US, whose systems looked vulnerable. Any organization still running an exposed PeopleSoft server should treat patching as urgent, because a firewall rule alone is not enough. The Hacker News
Crypto exchange Bitget loses nearly $388 million!
Bitget detected unauthorized transfers from its hot wallets on September 24. The exchange first reported a loss of about $351.6 million, and later reports put the total near $387.5 million. Bitget’s CEO said the attackers did not steal private keys. Instead they tricked the exchange’s own approval system into authorizing the withdrawals.
On Monday, Bitget said the attacker got in through a flaw in a third-party security product. That let them obtain high-level internal credentials, which they used to send fraudulent withdrawal commands. Cold wallets were untouched, and a user protection fund worth more than $464 million will cover the loss. Suspected North Korean threat actors are being blamed, and Bitget is working with Mandiant and SlowMist. The Hacker News Fortune
Citrix NetScaler zero-days exploited around the world!
Citrix confirmed that two critical NetScaler ADC and Gateway flaws, CVE-2026-88771 and CVE-2026-88772 (both CVSS 9.5), were exploited before a fix existed. The first lets an unauthenticated attacker run commands on devices in their default setup.
CISA added both flaws to its Known Exploited Vulnerabilities catalog on September 27 and told federal agencies to patch by September 30. Reports say the flaws were exploited for weeks before the public disclosure, and some administrators shut down their appliances before the fixes arrived. Help Net Security
SharePoint and MikroTik flaws added to the CISA exploited list!
CISA added a Microsoft SharePoint flaw (CVE-2026-65660, CVSS 8.8) and a MikroTik RouterOS flaw (CVE-2026-67279) to its exploited-vulnerabilities list on Friday. Microsoft first described the SharePoint bug as a spoofing issue, then updated its advisory to say attackers can use it to run code remotely.
The RouterOS flaw is part of an attack chain nicknamed “MikroTrick” by CERT Polska, which can give attackers admin control of a router. Administrators should update to the fixed RouterOS versions and check for unknown users, scripts or configuration changes. SecNews The Hacker News

OpenAI agent breaks into Australia’s Medicare statistics portal!
Australian Prime Minister Anthony Albanese revealed that an AI agent on an internal OpenAI research task got around access controls on a Medicare statistics portal in June. The agent reached files that were not public, and no personal information is believed to have been accessed.
OpenAI says it found the activity in August and told the government on September 10, through an email to a public mailbox. Albanese called the delay unacceptable. The portal has been taken offline, the Australian Signals Directorate is helping with a forensic investigation, and the government has set up a taskforce to review how it handles AI-related cyber incidents. The Hacker News
Hacker uses AI agents to steal 600,000 credit cards!
Forbes reports that a Chinese-speaking hacker used AI agents to hit as many as 100 companies in about five days, taking more than 600,000 payment card records. Security firm Gambit Security found the operation after the attacker accidentally left the server infrastructure exposed online.
The attacker reportedly combined DeepSeek, Kimi and an older Claude model with open-source agent tools, at a total cost of only about $8,000. Gambit says the agents installed card skimmers on checkout pages and that some cleanup routines even deleted victims’ data. It is a stark example of AI lowering the cost of large-scale cybercrime. CybersecAsia Forbes
JadePuffer’s AI agents wreck Azure environments!
Microsoft, which tracks the JadePuffer ransomware operator as Storm-3168, detailed attacks in which an AI-driven agent used two compromised service principals to map an Azure environment and steal storage keys. In a destructive burst, it deleted more than 100 storage accounts, and it also targeted Key Vaults, Function Apps and virtual machines. Azure resource locks protected some accounts.
Some experts caution that the evidence shows coordinated automation rather than proof that AI directed every step. Microsoft’s advice is still practical: use least-privilege access, scan for leaked secrets and turn on cloud workload protection. CSO Online BleepingComputer
Japanese railway group Keio hit by ransomware!
Keio Corporation, a major Tokyo-area railway operator, confirmed a ransomware attack on its group servers in the early hours of September 26. The company shut down parts of its network and reported the incident to the police. Hotel reservations and some card payments were disrupted, but trains kept running. No ransomware group has claimed the attack so far. Keio is still investigating whether customer or partner data was accessed. Rus Tourism News BleepingComputer
Healthcare firm Astrana breached through a spoofed phone call!
Astrana Health told the SEC that attackers impersonated company staff and spoofed its main corporate phone number to trick employees into giving them access to systems. The company reset credentials, restricted remote access tools and restored some systems from clean backups.
Astrana says the intruders accessed and copied private and confidential information. The company is still working out whether patient, employee or provider data was involved, and it has not said whether ransomware was used. SecurityWeek The Record
Fake “placeholder” domain now serves ClickFix malware!
Researchers at Manifold Security found that “third-party[.]com”, a domain widely used as a documentation placeholder, has been serving a ClickFix lure to Windows users. The fake Cloudflare check tricks people into pasting a malicious PowerShell command into the Run dialog.
The domain appears in more than 1,700 public GitHub repositories, including AI agent and MCP documentation. Manifold also flagged 13 other placeholder domains that are not reserved, and two of them serve scareware to Mac users. Developers should stick to the reserved example.com family for documentation. The Hacker News
New Android banking trojan console uses Gemini to pick its victims!
Cleafy says the operators of the RatHat Android banking trojan run a web console that collects stolen texts and passwords entered into fake bank login screens. Researchers have traced nearly 100 deployments of the console since April.
The newest version asks Google’s Gemini to estimate each victim’s bank balance from their messages, then sorts infected phones into high-value and mid-value groups. Cleafy found no sign that the AI moves money itself. It only helps criminals decide which victims are worth their time. The Hacker News
Apple patches a possibly exploited zero-day!
Apple released updates for older versions of iOS, iPadOS and macOS to fix CVE-2026-86950, an out-of-bounds write in CoreGraphics. Processing a malicious file could lead to arbitrary code execution. Apple says it may have been used in an extremely sophisticated attack on specific targeted individuals.
Apple credited Meta Product Security with finding the bug, but gave no details on who was targeted. Users of older devices and operating systems should update right away. The Hacker News
Elementor flaw could let attackers take over WordPress sites!
Patchstack disclosed a high-severity cross-site request forgery flaw (CVSS 8.8) in the Elementor WordPress plugin, which is active on more than 10 million sites. If a logged-in administrator clicks a crafted link, an attacker can create a rogue admin account.
Only versions 4.3.0 and 4.3.1 are affected, but those two versions have been installed on more than 2 million sites. Site owners should update the plugin and avoid clicking unexpected links while logged in as admin. The Hacker News

Ex-soldier gets 70 months for AT&T, Snowflake data thefts!
Cameron Wagenius, a former US Army soldier who used the alias “Kiberphant0m”, was sentenced to 70 months in prison and ordered to pay nearly $295,000 in restitution. He hacked and extorted telecom and tech companies, including AT&T and Verizon, while serving on active duty.
The case is tied to the wider Snowflake data-theft campaign, which hit more than 165 organizations that had not enforced multi-factor authentication. Prosecutors said he made only around $1,500 from selling stolen data. Co-conspirator Connor Moucka is due to be sentenced on October 27. Help Net Security Krebs on Security
Ryuk ransomware member sentenced to two years!
Karen Vardanyan, an Armenian national extradited from Ukraine, was sentenced to 24 months in US federal prison and ordered to pay about $1.2 million in restitution. He took part in Ryuk ransomware attacks on companies, schools and other organizations between 2019 and 2020.
Ryuk was a major ransomware-as-a-service operation that targeted hospitals during the COVID-19 pandemic. The gang behind it later moved on to Conti. BleepingComputer US Department of Justice
CISA releases 2026 election security plan, 40 days before the midterms!
CISA released its 13-page 2026 Election Infrastructure Security Plan on September 24. It lists no-cost, voluntary services for state and local election officials and names CISA’s 10 regional directors as election security advisers.
Election officials have criticized the plan as late and inadequate. They say services such as tabletop exercises and penetration tests were unavailable this cycle after cuts to the agency’s election work. Some states paid for private services instead. AP via U.S. News
General Manager
General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.
LinkedIn Profile →Take control of your DMARC reports
Turn raw XML into actionable dashboards. Start free - no credit card required.