This week

- ShinyHunters breaches FBI systems
- OpenAI agents broke into Aussie government system
- NHS Trust accidentally overwrote maternity records
Interesting stats
1,787 US water and wastewater organisations have passwords or credentials leaked by Infostealer malware, according to SpyCloud.
0.5% of Project Glasswing — Anthropic’s invite-only cyber programme — vulnerabilities have gone on to be exploited in the wild, and just 26% of AI-generated vulnerability fixes actually eliminated the issue, and 54% of the time they didn’t, or introduced another security issue. LINK
£1.3 billion ($1.7B) spent by the Kremlin on “manipulating information,” according to UK Prime Minister Andy Burnham, who announced new plans to fight disinformation.
Three things
-
ShinyHunters poked the ~bear~ eagle(?) this week, ’seizing’ (defacing) the FBI Jobs website and claiming to have stolen sensitive information on all the bureau’s 38,000 staff. The group says it was “offended” by a May FBI advisory saying ShinyHunters may exaggerate claims, and said, “We wish to state unequivocally our threats and claims are very real,” before demanding the advisory be updated. The underlying vulnerability is allegedly in Oracle’s PeopleSoft platform and allowed the group to gain access to background check, medical, and investigation information. Reuters reports that some of the data contains details about sensitive work against Chinese spies, Russian intelligence and drug cartels. This is bad news for the FBI and their undercover agents and while this was a zero-day vulnerability, they’re the kind of systems that I image are routinely targeted by foreign powers and organise crime. But it’s also bad news for ShinyHunters on two fronts: I can’t imagine that the full US law enforcement machine won’t be pointed at them, but also a bunch of intelligence agencies interested in the FBI’s counter-intelligence operations will also be targeting them to get hold of the juicy data they claim to have stolen.
-
OpenAI agents went rogue (again) and broke into an Australian government system to find health statistics because it couldn’t look them up on the web. OpenAI failed to detect or prevent it in the moment (again), only finding what it calls “misaligned model activity” in August, when it then fired off an oops to a generic Australian government email. Australian Prime Minister Anthony Albanese described the incident as “obviously unacceptable” and said OpenAI took “way too long” to detect the incident and inform his government. Fortunately, it was a portal containing non-sensitive information. Still, the relentless pursuit of goals that we’re seeing in AI models is giving many cause for concern (despite some stats suggesting they’re not really very good at the cybers, see above!) Meanwhile, OpenAI also fessed up this week to leaking 53 images from ChatGPT users, declining to say whether its systems generated them or were user-uploaded images. There’s obviously a big effort underway inside OpenAI to comb through logs and find cases where the frontier lab’s systems have done undesirable things or committed crimes. OpenAI has disclosed over 15 incidents since first admitting that agents had broken containment. In a British understatement, I’d suggest that it’s not great.
-
Not-a-data-breach: Human error at Nottingham University Hospitals Trust led to the loss of 11 years of records for who viewed maternity records. Patient-care related records, such as “notes, observations, test results” etc, were recoverable, however the logs of if/who viewed by a particular person between September 2011 and November 2022 was lost. The mix-up occurred while reusing a script used on another system, and someone trying to create a copy of a radiotherapy database accidentally overwrote the maternity database. It matters because police are currently investigating allegations that over 500 mothers and babies faced “potentially avoidable” harm at NUH NHS Trust. Those records would have been useful in establishing who accessed what, when, which I’m sure is distressing for both sides.
In brief
-
OpenAI will share its Daybreak cyber defence tooling with Ukraine to help defend the country against cyber-attacks.
-
CISA has published a white paper (PDF) on how it will improve the CVE programme in the ‘Quality Era’, including improvements to CVE record content, data infrastructure, programme governance, and ecosystem participation.
-
Police in Wales say staff information may have been “accessed or compromised” during an incident detected on 14 September. No personal data relating to the public is thought to have been compromised, and disruption was limited to non-emergency systems, Dyfed-Powys Police said.
-
Researchers have devised a new way to break RSA keys without factoring. Signature forgery drops the compute required by an order of magnitude, potentially putting 2048- and 4096-bit keys for blind-signature RSA implementations within practical reach.
-
Ping-pong: Belgian table tennis organisations and gymnastics federation have suffered cyber-attacks, and a cybercriminal has claimed to have stolen data of hundreds of thousands of individuals across the breaches.
-
Google says that ShinyHunters have updated their tooling to bypass common WAF rules. The cybercrime group has been targeting Oracle PeopleSoft with an unauthenticated RCE vulnerability (CVE-2026-35273; 9.8/10; advisory). The tweak is to use percent-encoded version of the letter P so
/PSEMHUB/(the path used in the exploit) becomes/%50SEMHUB/. Many WAFs do literal comparisons and miss that these are the same path. -
Kiteworks (neé Accellion), which built the file transfer appliance that was widely exploited in recent years, has cautioned customers to shut down their systems. Kiteworks CISO Frank Balonis told TechCrunch they had “received credible threat intelligence from law enforcement” and “Out of an abundance of caution,” had “recommended a precautionary shutdown window”. I’ve not seen anything further this weekend.
-
Citrix has confirmed active exploitation of critical emote code execution and buffer overflow vulnerabilities in its NetScaler suite (CVE-2026-88771 -88772 respectively; both 9.5/10; advisory).
-
Meta’s MacOS Muse AI app has an undocumented setting that can be used to redirect voice dictation functions, and potentially allowing access into the app’s ’Secure VM’ and user’s account. This is the sort of thing you’d expect to have been picked up in threat modelling, especially given the song-and-dance that Meta has been making over how, ahem, privacy-conscious the ad business is. Patrick Wardle discovered the vulnerability and notes it’s not remotely accessible, but it could be abused by other local malware.
-
F5 has patched a critical remote code execution zero-day in its BIG-IP Access Policy Manager (APM) product (CVE-2026-94127; 9.8/10; advisory).
-
Ireland’s Data Protection Commission has fined Google €403 million for GDPR breaches following an investigation into how the search giant processes location data. From 2018 to 2020, removing ‘Location History’ from a user’s Google profile removed only mobile data, not anything collected or inferred from web searches and stored separately in the innocuous-sounding ‘Web & App Activity’.
-
House Democrats have introduced legislation proposing a ‘force structure assessment’ to ascertain if the US Cybersecurity and Infrastructure Agency has the staff it needs to do its job. Cuts at CISA have led to around one-third of staff leaving the organisation in about a year.
-
Microsoft and industry partners have disrupted the EvilTokens phishing-as-a-service cybercrime platform, seizing 50 websites and disabling a further 175 domains. Although EvilTokens launched only in February this year, Microsoft says around 1,000 cybercriminals used the platform, and its investigators linked it to over 12,000 compromised Microsoft customer mailboxes. The UK’s Metropolitan Police have arrested two men, aged 32 and 38, in connection with running the platform, which was available on Telegram for an initial $1,500 fee, then a $500 monthly subscription.
-
An Armenian national has received a two-year prison sentence for charges in relation to the Ryuk ransomware operation. Karen Vardanyan, 35, pleaded guilty in July and will also pay $1,219,106 in restitution and will have three years of supervised release.
-
Gen Digital is in talks with domain registrar GoDaddy about a potential acquisition. Gen Digital formed in 2022 from the merger of NortonLifeLock and Avast, and has since acquired other consumer-focussed security companies.
And finally
- North Korean attackers are believed to be behind a $351 million cryptocurrency theft from the Bitget exchange. Bitget has suspended transfers, and Chief Executive Gracy Chen posted on social media saying, “The full amount of this loss falls within the coverage of Bitget’s User Protection Fund”. Around half of the $83 million in Ripple (XRP) stolen has been moved by the attackers, potentially hampering recovery efforts. XRP’s architecture does not support a mechanism to freeze transactions relating to a specific wallet. If only there were organisations that would protect your assets, and a system that could trace and recover your funds? ;-)