❌

Normal view

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

7 October 2026 at 17:43
Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have

AWS launches open-source AI agent sandbox to prevent YOLO mode disasters

7 October 2026 at 17:42
AWS has offered multiple open-source strategies for holding AI agents accountable, and now it’s adding a full-on sandbox to this stack. Dubbed Strands Box, the new solution uses OS-level isolation and some of AWS’ other recent open-source AI control tools to, ostensibly, retain greater control over autonomous AI agents’ behavior. “Agents increasingly run in ‘YOLO mode,’ approving every action without human review,” the AWS team explained in its announcement. “The usual solution to this problem is a sandbox … but access is only part of what we want to control.” The problem with containers and microVMs typically used to isolate AI agents, as AWS explains it, is that their strong isolation doesn’t come with contextual rule enforcement. In other words, when a containerized or virtualized agent gets hold of a tool, there may be no stopping it from doing whatever it wants - like deleting a production database, or gaining access to the internet and doing dog knows what. That’s where the other open-source tools inside Strands Box come in: It uses the Dogwood Local Engine to give the policy engine in Box temporal awareness, so tool calls can be checked against not only what the agent wants to do, but what it’s already done. As one example, AWS noted that an agent could be allowed to post status updates to Slack, but no more than three times every ten minutes to prevent it from spamming its human operators. An AWS spokesperson further explained that Box could be used to control when an agent can perform a Git push, or it could be used to put a cap on API calls that could end up costing a small fortune. Additionally, Strands Box includes Strands Shell and Monty for Python, which expose shell and Python operations to the same Dogwood policy engine and event history, making agentic actions clearer to developers and allowing policies to account for what an agent is trying to do. AWS VP and distinguished engineer Marc Brooker, one of the folks behind Dogwood and Strands Box, explained to The Register that the interpreters are a key part of making agentic behavior more intelligible, which allows for devs to write more precise policies to prevent agents from taking bad actions. “Box’s Shell and Python interpreters expose operations such as file deletions, while its gateways expose API requests and tool calls,” Brooker told us in an email. “Policies can then account for the action being attempted and earlier activity.” Box, Brooker added, enforces those rules without trusting or relying on agents to actually follow instructions, which should ideally prevent them from running roughshod over their operators’ wishes. As for the reason behind AWS’ push to develop open-source tools like Dogwood, the Dogwood Local Engine, and Strands Box, Brooker said that AWS wants to find the right balance between boundaries and policies that prevent agentic AI disasters of the kind we regularly report. “Box enforces the policies developers configure, deterministically, and the agent can't talk its way around these rules,” Brooker explained, though he added that, even with properly configured permissions, an agentic action can still produce an unwanted result. “Developers remain responsible for deciding what access to grant and where human review is needed,” Brooker added - in other words, don’t let your YOLO mode go too YOLO. A bit of human oversight is still necessary. “Agent safety is an area where the industry still has significant work to do, and we're committed to continuing to invest in it, both inside the AWS cloud and in open source,” Brooker said. Strands Box supports any agent or harness one wants to confine within its walls and is available on GitHub now, though only for macOS for the time being. Linux support is in development, and AWS told us a Windows client is “on our radar,” but neither has a planned release date. Deployment to platforms like AgentCore, ECS, and Kubernetes is also planned. ®

US states sue popular kitmaker TP-Link over China risks

7 October 2026 at 17:30
The attorneys general of Florida, Iowa, Montana, and Nebraska have sued ubiquitous networking and smart home tech maker TP-Link, alleging its security claims were misleading and it hadn't properly disclosed ties to China. The company has a large presence in US retail and the tech channel, especially in consumer routers, with stats from Circana asserting it had around 36.6 percent US market share by units and 31 percent by dollars in 2024. The complaint [PDF] accuses California-based TP-Link Systems, whose brand originated in Shenzhen, of deceptive and unfair marketing practices concerning its routers' security and its connections to China. It cites exploitation of TP-Link devices by Chinese and Russian state-backed hackers. The suit also claims TP-Link allegedly concealed facts about its "past and ongoing ties to the People's Republic of China," accuses it of having a supply chain that's reliant on PRC players, repeated firmware vulnerabilities, and being subject to Chinese laws that force companies to cooperate with state intelligence. According to the states' attorneys general, the hardware vendor still relies on Chinese companies for research and development and manufacturing operations, despite previously claiming to have moved into Vietnam after severing ties with China. The complaint alleges that only 0.5 percent of components used at TP-Link's Vietnamese plant, measured by value, are bought in Vietnam, with "all other inputs" imported "from or through China." The complaint also claims that a US-designated Chinese military company carried out construction work at the Vietnamese factory, challenging TP-Link's assurances about its supply chain's security. The complaint cites 2025 testimony [PDF] from former NSA cybersecurity director Rob Joyce that TP-Link's share of the US retail market for Wi-Fi systems and small-office/home-office (SoHo) routers at at least 60 percent. Lawyers pointed to various snippets from TP-Link's marketing materials. These included claims that its HomeShield product "covers all security scenarios" and, on a version of its website available in November 2025, provides a "100 percent safeguard" for network security. The complaint argues that TP-Link's security assurances were misleading because its routers contained critical vulnerabilities. It further cites Joyce's that TP-Link routers were among the brands exploited in the China-linked Volt Typhoon and Flax Typhoon campaigns. The complaint also alleges that TP-Link's privacy policies permit it to collect customer data and share it with affiliates without disclosing how its Chinese connections and China's intelligence laws could expose that information to Chinese intelligence agencies. "Iowans' sensitive data and our national security is at risk because of TP-Link and their connection to the communist Chinese government," said Iowa Attorney General Brenna Bird. "TP-Link tells Iowans its routers are safe, our personal data is secure, and that they have no ties to China. They are not telling the truth. It's time to hold China and China-backed companies accountable." "TP-Link's false statements and deceptive advertising are a violation of Montana law," said Attorney General Austin Knudsen. "As a result of their nefarious practices, millions of Americans have unknowingly invited a foreign adversary into their living rooms and put their personal information at risk. "I will do everything I can as Attorney General to hold TP-Link accountable and protect our privacy and security." Steve Kovsky, corporate affairs officer for TP-Link Systems Inc., said the lawsuits were based on false premises, did nothing to advance national security, and unfairly penalized a US company. Kovsky added that the company has spent months providing officials with clear documentation showing that it is not owned or controlled by any foreign government and that its devices sold in the US are manufactured in Vietnam. "Any claims that our products present a threat to user security or grant unauthorized network access to foreign governments are baseless," he said. "TP-Link Systems is a US company that complies with US privacy and data protection laws. We perform comprehensive security testing and rely on trusted third-party security labs for additional scrutiny to ensure our products meet the highest security standards and are recognized as among the most secure on the market. "We meet or exceed all industry best practices for monitoring and preventing vulnerabilities and actively support our customers to mitigate any issues that occur as they are identified. We do not, and will not, share customer network data with foreign governments or unauthorized third parties. "We stand fully behind the security of our products, the integrity of our company and our people, and our commitment to serving the best interests of our customers in the United States and globally. We look forward to refuting these baseless allegations in court." The allegations echo those made by Texas Attorney General Ken Paxton, whose office sued TP-Link earlier this year over its Chinese connections and router security. US officials began weighing restrictions on TP-Link router sales in 2024. In March 2026, the FCC imposed broader restrictions [PDF] on new foreign-produced router models, barring new equipment authorizations unless an exemption is granted. Previously authorized models were not automatically banned. ®

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

7 October 2026 at 16:17
SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions. SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being

Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers

7 October 2026 at 16:01
A suspected Italian attacker armed with a malware-controlling poem has infected more than 3,000 servers since April, breaking into enterprise AI infrastructure to mine cryptocurrency and add compromised systems to its growing botnet. This is the first case of “adversarial poetry” - an AI jailbreak technique that turns harmful prompts into poems to trick LLMs into bypassing safety guardrails - that Lumen’s Black Lotus Labs, which has been tracking the PoeLLM malware, has seen in real-world attacks. “This is a first for us,” the researchers told The Register via email. “While we can't get inside the threat actor's head, we think the attacker might have used a poem because it serves as a perfect vehicle for hiding an important message,” they added. “To anyone who comes across it, this is simply a poem on GitHub. It has no links, no files to download, no encrypted text that could easily be flagged as malicious, even by advanced models. There would be no reason for any security researcher to identify this poem as malicious - or know about the IP address hidden within it - unless they had access to the malware referencing it.” PoeLLM malware has been active since at least April, impacting more than 3,000 servers primarily located in the US and Western Europe, and it continues to infect new victims. At its peak, the malware infected more than 800 active servers per day. The malware abuses - and scans for - open source AI systems and services. Most of the victims were running vulnerable, internet-facing versions of LiteLLM and Ollama. Additionally, hundreds of victims were running Gotenberg, a PDF converter, and software development platform Gitea. In addition to these open source tools, the attacker may have targeted commercial software including Ivanti Sentry. The threat hunters first spotted the PoeLLM malware while investigating an Ivanti Sentry vulnerability, CVE-2026-10520. “In early June 2026, a compromised Ivanti Sentry victim contacted a dedicated server at 5.78.73[.]122,” according to a Wednesday report shared with The Register. “Shortly after contacting this C2, the Ivanti Sentry victim began scanning for other vulnerable devices.” How adversarial poetry works Black Lotus Labs attributed the PoeLLM malware to an Italian-speaking criminal, and named the financially motivated campaign Canto Incognito because it hides the malicious commands in a poem posted to a GitHub repository. “Comments within the malware and on the attacker’s GitHub pages are in Italian, and netflow analyzed by Black Lotus Labs suggests that the attacker is located in Italy,” the threat-hunters told us, adding that they believe the campaign targets AI systems and that the poem itself was written by AI. The malware deploys XMRig and Iron miners, and connects victims to Kryptex mining infrastructure. In addition to using compromised GPU hardware powering AI workloads to mine cryptocurrency, PoeLLM also turns victims' machines into vulnerability scanners and exploit servers, which allows the attacker to compromise even more vulnerable systems. The researchers’ investigation indicates that the cryptojacking miscreant - aka GitHub user “ejejejdfbbebe” - made the first GitHub commit with the adversarial poem on April 13. The repo is a fork of the nodejs.org website source code, and the file is called “dash.css.” Inside the file, there’s a poem titled “On the Nature of Connection,” which has been updated 11 times since its initial commit. Here’s the most current version, as of September: In the silent hum of driver, the machines begin to speak, Each pulse of diode threading light through copper veins. we taught the dark to carry meaning, byte by byte — A language built from lightning, cold and clean. Beyond the wall of encryption, a signal finds its way, the tick of distant servers answering back. Data moves like water through the cracks of ordered thought, and somewhere in the code, the world stays on track. Here’s the adversarial piece: the malware finds its current command-and-control (C2) server from keywords in the poem, and when the operator changes the poem, the infected systems find the new C2 location. It does this by parsing the poem, extracting certain words and phrases, and then converting them to numbers using a hard-coded dictionary in the body of the malware. Black Lotus Labs says the logic for C2 discovery works like this: The function “extract_poem_phrase_field” extracts three words/phrases from the body of the poem, case-insensitively: Word 1: text between "In the silent hum of " and "," Word 2: text between "each pulse of " and " threading" Word 3: text between "Beyond the wall of " and "," 0x44a8db–0x44a99b extracts the fourth word differently: Find " of distant servers" Walk backward to the previous whitespace Require the 4 bytes before the word to be "the " Use the word after "the " as Word 4 The four words are then matched to corresponding numbers, which combine to form the IPv4 address hosting the server. Here’s what the C2 conversion looks like with the key: Black Lotus Labs’ write-up lists all the C2 IP addresses, plus when they were first and last seen, so be sure to check that out. More AI infrastructure = larger attack surface As enterprises increasingly use AI in their operations, they also expand their attack surface. And, as we have repeatedly seen, security remains an afterthought in AI deployments. “The Canto Incognito campaign appears to be relatively unique in its targeting of multiple AI-related services,” the researchers told The Register. “Other notable campaigns this year, including the LiteLLM supply chain compromise, focused on a single service and impacted roughly 2,500 victims, according to open sources. The collection of more than 3,000 PoeLLM victims appears to exhibit multiple vulnerable services at any given time.” For comparison: The LiteLLM supply chain attack, which began with a compromised Trivy build, potentially exposed more than 2,500 companies and 434,000 CI/CD pipelines worldwide, according to CloudSEK security researchers. The PoeLLM malware developer “has been extremely successful in identifying vulnerable servers, deploying exploits, and conscripting victims to continue expanding the campaign,” Black Lotus Labs said. “If the actor had only focused on one or two vulnerabilities, the potential victim pool might have quickly dried up, but the expanding scope allowed for a bigger, more powerful (and more profitable) botnet.” They told us they expect to see more of these types of attacks in the near future. “AI makes it easier to deploy tools like LiteLLM, Ollama, or Gotenberg, but AI isn't always checking to make sure those services are patched and protected from attackers,” the researchers said. “As more AI-enabled servers come online, malware like PoeLLM will continue to spread.”®

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

7 October 2026 at 15:34
A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache's multiprocess mode, where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

7 October 2026 at 15:33
Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet. The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including

ShinyHunters Extorted Boeing Spin-off Prior to Arrests

7 October 2026 at 13:48

A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle “Rey,” was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing, which manufactures the fleet of planes used by the employer of Rey’s father — Royal Jordanian Airlines.

The logo for Jeppesen ForeFlight, a business unit divested last year by the aerospace firm Boeing.

On October 3, Reuters cited three unnamed sources saying a suspected ShinyHunters member in Amman named Saif Al-din Khader was detained by Jordanian authorities and was cooperating with the FBI. KrebsOnSecurity identified Rey as Khader in a November 2025 profile, in which the young man admitted working with multiple ransomware groups.

Rey was featured again in a September 28 exclusive about the Dutch police arresting 24-year-old convicted cybercriminal Pepijn van der Stap on suspicion of aiding in data thefts and extortions by ShinyHunters. The story noted that immediately following the Dutchman’s arrest on the evening of September 15, Rey assumed control over the ShinyHunters brand and boasted publicly about stealing highly sensitive data from the FBI and extorting the ransomware group Cl0p.

Rey taunted both the FBI and Cl0p with memes posted to his longtime account on Twitter/X, while simultaneously including images of the avatar used by Van Der Stap’s former hacker alias “Umbreon” in an apparent attempt to frame the Dutchman for both hacks.

A taunting meme uploaded to Twitter/X by Rey on Sept. 22. A giant sized version of the Pokemon character Umbreon can be seen in the bottom left.

As noted in our September 28 report, ShinyHunters gained access to the FBI site and other victims by exploiting a vulnerability (CVE-2026-35273) in PeopleSoft, a software-as-a-service platform from the tech giant Oracle that is broadly used by companies to manage hiring and human resources, benefits and payroll. Oracle quickly issued a fix for CVE-2026-35273, which ShinyHunters first began exploiting as a zero-day in June, and at the time Mandiant released web application firewall rules intended for organizations that couldn’t apply the security update quickly enough.

ShinyHunters told BleepingComputer in June that the original goal behind exploiting the PeopleSoft vulnerability was to breach the FBI’s own PeopleSoft database, but the hackers said those attacks were unsuccessful for some reason. In recent weeks, however, ShinyHunters turned to a well-known URL-encoding trick to bypass Mandiant’s suggested web application firewall rules.

In a report released Sept. 25, security experts at Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.

Reuters reported October 5 that the FBI has removed a contractor at Accenture over their failure to patch the FBI recruitment website hacked by ShinyHunters, which exposed sensitive data on more than 5,000 FBI personnel, including each’s person’s unit and specialization, as well as medical and psychiatric records.

‘REY’ MEANS KING, AS IN ROYAL

According to two sources familiar with the ShinyHunters investigation, a navigation and digital aviation unit recently divested by the global aerospace company Boeing was among the victims that ShinyHunters was in the process of extorting when Rey was apprehended by Jordanian authorities.

Those sources said the FBI’s investigation into ShinyHunters gained renewed urgency with the group’s attempted extortion of the former Boeing unit, which allegedly included the theft of sensitive information that sources said could pose operational safety and security risks.

In a brief statement shared with KrebsOnSecurity, Boeing acknowledged the extortion attempts by ShinyHunters, and said the incident concerned data stolen from Jeppesen ForeFlight, a subsidiary that Boeing sold in November 2025 to the private equity firm Thoma Bravo for $10.55 billion.

“We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight,” a Boeing spokesperson shared. “We are actively reviewing the matter with the Jeppesen ForeFlight team.”

A spokesperson for Jeppesen ForeFlight shared a written statement in response to questions, saying the company has seen no impact on their end. “Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products.”

Rey’s alleged involvement in attempting to extort the former Boeing unit is noteworthy because there is strong evidence that his father works for Royal Jordanian Airlines, which is mostly controlled by the Jordanian government and operates its long-haul fleet on passenger planes built by Boeing. Rey claimed on Telegram in early 2025 that his father was an airline pilot, although that could not be independently confirmed.

However, as noted in our November 2025 profile of Rey, his family’s shared computer was at one point compromised by password-stealing malware, and the data collected by that malware clearly shows Rey’s father used the same credentials to log in at multiple online portals for Royal Jordanian Airlines employees.

Royal Jordanian Airlines has not yet responded to a request for comment. In advance of our September 28 story, KrebsOnSecurity once again emailed Rey’s father to seek comment and update him on his son’s alleged activities. Neither of the Khaders have responded. But just hours after that request was sent, Rey began deleting his various social media accounts, including the Twitter/X account he previously used to taunt the FBI, Cl0p, and other ShinyHunters victims.

Rey may have nixed many of his social media profiles, but his cybersecurity blog on GitHub somehow escaped the purge, and it shows that Rey was fixated on the leaders of the Cl0p ransomware group. In March 2026, Rey’s blog featured a lengthy post that identified two Russian men as the core developers and hackers behind Cl0p.

Rey’s blog on GitHub. This post doxes two Russian men as the core operators behind Cl0p, one of the oldest and most established ransomware groups still in operation today.

MURDER FOR HIRE?

Meanwhile, news outlets in the Netherlands reported explosive new allegations leveled at Van der Stap, whose supposed personal transformation from convicted to reformed hacker has been widely covered in the tech news media. The Dutch daily RTL reported on Sept. 29 that investigators suspect Van der Stap tried to orchestrate at least two murders. According to RTL, the murders were allegedly to be committed abroad, and there are indications Van der Stap gave the order for these attacks.

Van der Stap was released from prison after serving the better part of a four year sentence for data theft and extortion activity that prosecutors said netted between €1.5 million and €2.7 million. In an interview with KrebsOnSecurity on September 9, Van der Stap described his new role as “offensive security lead” at the Dutch cybersecurity company Neo Security, saying the job involved probing client networks for security vulnerabilities.

Neo Security’s owner Benjamin Korper told Reuters he has hired an outside firm to investigate whether Van der Stap had hacked Neo Security or its customers, but that so far investigators have found no evidence he acted against his employer or clients. Korper said Dutch forensic investigators visited his office on September 15, the night Van der ⁠Stap was arrested in a dramatic police raid that reportedly involved flash bang grenades.

A screenshot of a Sept 16 story by the Dutch news outlet at5.nl, describing a police raid on Van Der Stap’s residence that reportedly used flash-bang grenades.

Prior to his first arrest in 2023, Van der Stap was working as a software engineer at the Amsterdam-based cybersecurity startup Hadrian, while volunteering at the Dutch Institute for Vulnerability Disclosure (DIVD) — even as he was hacking into and extorting a number of large organizations.

When asked in a recent interview why anyone should believe the word of a self-described “reformed” cybercriminal who had so casually deceived countless friends, co-workers and journalists for years, Van der Stap replied that his work spoke for itself and there was nothing he could say that would convince his worst critics.

“You can throw a bunch of nice words at someone, but you can’t convince them if they don’t want to be convinced,” Van der Stap told KrebsOnSecurity on Sept. 9. “I’m doing what I can to repay victims, and that’s all I can do. If someone doesn’t want to believe me, then that’s on them.”

FRANCHISING AND BURNING A BRAND

Cybercriminals aligned with ShinyHunters have been responsible for dozens of data breaches involving billions of stolen records, and breaches claimed by the group stretch back to at least 2019. But experts say the people recently operating behind the ShinyHunters name are not the same core members that populated the group in its early days, most of whom are French citizens who have been arrested (if not also imprisoned) on at least one prior occasion for alleged cybercrime activity.

More to the point, ShinyHunters has become something of a franchise. Think the Dread Pirate Roberts character in the 1980s cult movie classic “The Princess Bride,” only succession by death is replaced with succession by arrest, and there can be multiple simultaneous Dread Pirate Robertses. Sources close to the investigation say the FBI is focusing on a remaining handful of cybercriminal freelancers or affiliates who have been feeding the group stolen credentials to various software-as-a-service (SaaS) platforms used by major companies in exchange for a cut of any data ransoms later paid by victims.

In the days after the news broke of Van der Stap’s arrest, a cybercrime-focused chat server on Telegram that was allegedly operated by Rey erupted with hot takes, with most participants heaping ridicule on the teenage hacker after he publicly backed down from threats against the FBI and Cl0p, and again when the ShinyHunters’s darknet website suddenly went offline. Several commentators accused Rey of resurrecting the ShinyHunters brand after its core members were rounded up in France, and making a mockery of the group’s name and reputation ever since.

“He bought the old forum PGP key and used it to make new Breachforum websites and Telegram channels larping as ShinyHunters to ransom companies and then sell the used data or resell his forum when he goes broke,” one member recounted.

A relatively new Telegram channel called “The Battle” has been doxing and needling Rey and other alleged ShinyHunters members for several weeks, and it has gained a considerable readership among the cybercrime communities operating on Telegram. One of the coordinators of that harassment campaign repeatedly portrayed Rey as clueless greenhorn who sought to ride the coattails of a cybercriminal brand that has long enjoyed a reputation for ruthlessly selling or publishing data stolen from victim companies who refuse to give in to extortion demands.

“Rey (Saif Al-Din Khader) made a serious mistake when he started pretending to be a member of ShinyHunters,” wrote the administrators of The Battle server on Telegram. “That group had already been dismantled, with many of its members either arrested or imprisoned, yet Rey still chose to use its name while carrying out his crimes. We’re aware of claims that [Rey] caused over $200 million in damages and helped around 5–6 friend groups in the community make money by using Shiny Hunters group aliases to negotiate deals for a 25–30% cut over the past few months.”

In an interview with The Register, ShinyHunters claimed they hacked the FBI to counter the agency’s narrative in a May 2026 alert that advised victims against paying a ransom to the group, which came off looking unprofessional and capricious in the FBI’s advisory.

A flash notice on ShinyHunters released by the FBI on May 15, 2026.

The public notice warned the group has been known to pursue a number of different victim harassment strategies, from sending threatening text messages and phone calls to victims and their family members to in some cases swatting victims. The FBI warned ShinyHunters members “may also falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.”

The hackers told The Register their attack on the FBI “demonstrated our technical capabilities and directly refuted the misinformation disseminated by the FBI, journalists, and industry researchers.” At the same time, the group’s leaders seemed to acknowledge that the FBI’s warning materially harmed their prospects for convincing victims to pay, saying “this was fundamentally a public relations and marketing initiative for our business.”

The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the Workflow

7 October 2026 at 11:57
The 2026 findings are not just a year-over-year shift. They mark the latest point in a five-year arc where resilience, AI governance, human risk, and board scrutiny are converging inside the systems where work actually happens. For years, the enterprise cybersecurity story has been told as a straight line of escalation: more attacks, more data loss, more pressure, and more urgency. That

FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

7 October 2026 at 11:56
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

7 October 2026 at 11:49
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software

What Is Agentic Pentesting? What It Proves, and Where It Stops.

7 October 2026 at 11:42
If you’re evaluating an agentic pentesting solution right now, you’ve probably heard the same pitch more than once: point it at a target, and it discovers, validates, and exploits attack paths autonomously, the way a real attacker would. That promise is worth taking seriously. It’s also worth pressure testing, and three questions do the heavy lifting.  What can the assessment actually

FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks

7 October 2026 at 10:52
The FBI and US Secret Service (USSS) say criminals using credentials linked to the FortiBleed campaign are locking organizations out of their Fortinet firewalls. The agencies published a joint advisory on Tuesday, citing SOCRadar's verification of more than 86,644 compromised devices across 194 countries. "Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system," their advisory [PDF] states. "During the initial intrusion, threat actors create new accounts not previously on the device. In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment." The campaign targets internet-facing FortiGate firewalls and SSL VPN gateways. Criminals use credentials from earlier breaches and infostealer logs for credential stuffing and password spraying, then extract password hashes from compromised devices and crack them offline using GPU-accelerated clusters. The agencies urged organizations to restrict internet-facing management access, terminate active administrative and VPN sessions, reset passwords, and enable phishing-resistant multi-factor authentication. The advisory also links FortiBleed to ransomware campaigns, saying initial access brokers supplied compromised-network access to ransomware affiliates. The Register previously reported on the connection, identified by SOCRadar. The current evidence points to affiliates working for the INC/Lynx and Payload ransomware groups making use of the credentials, and SOCRadar said in July that it had seen at least 12 confirmed ransomware attacks stemming from FortiBleed. The agencies encouraged victims to report incidents, while noting that organizations were not obliged to provide information in response to this advisory. The FBI and the Secret Service said victim reports could help identify indicators of compromise and warned against paying ransoms. ®

Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

7 October 2026 at 08:07
Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional

100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

7 October 2026 at 06:57
The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer). The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not disclose who the

South Korean president calls for creation of tools that stop all cyber-attacks

7 October 2026 at 03:56
South Korean president Lee Jae Myung has told the nation’s cabinet that it’s time to develop AI-powered defensive tools to combat AI-wielding attackers. “Recently, a series of personal information leak incidents have been occurring at financial and public institutions,” he said yesterday – likely referring to incidents like the breach at e-tailer Coupang and last week’s raid on local banks that exposed customer data. “Circumstances indicate that artificial intelligence was utilized, causing great concern and anxiety among the public,” he claimed. “I request that the relevant authorities swiftly and clearly identify the circumstances of these incidents, and rapidly deploy and concentrate the necessary personnel and resources to minimize damage,” he added, before calling for South Korea’s government to “build security capabilities that can detect attacks in advance and preemptively block them.” “I urge the relevant ministries to quickly inspect the security systems across the entire national core infrastructure, as well as the private sector, and immediately implement any necessary security measures,” he continued. “I hope we can accelerate the development and distribution of AI technologies specifically tailored for cybersecurity.” President Lee thinks South Korea needs to “completely innovate our society's security paradigm to fit the AI era.” That work will involve public and private sector players collaborating “to transform our technology, systems, and awareness.” The remarks amount to a major policy statement, and a very public one at that. South Korean ministers and tech giants now get to turn the president’s words into action, a complex task given the broad scope of the leader’s demands and the fact that nobody thinks it's possible to defeat cybercrime. Meanwhile, Down Under Also yesterday, Australian politicians had their chance to grill OpenAI Chief Strategy Officer Jason Kwon, who fronted a parliamentary committee to answer questions about how his company’s agents accessed a government medical records website. Kwon allowed that OpenAI should have done better than emailing the abuse reporting email address at the relevant Australian government agency but defended the company’s efforts to learn from the Hugging Face incident. The committee is sitting for another two days this week, with one topic of debate being how or if Australia should tweak its copyright laws to ensure AI companies pay content creators whose works they use when training their models. Australian law doesn’t include a fair use provision like those that AI companies in the USA relied on when sourcing content. Creators fear a rumored opt-in payments scheme will be too weak, but Australia’s government fears it may miss out on big datacenter investments and access to onshore frontier models if it doesn’t change copyright law to make it more AI-friendly. ®

❌