Security
ShinyHunters claims FBI breach via Oracle zero-day, 3TB stolen
ShinyHunters says it hacked the FBI through an unpatched Oracle PeopleSoft zero-day, stole up to 3TB, and defaced the FBI jobs site.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
ShinyHunters claims FBI breach via Oracle PeopleSoft zero-day
ShinyHunters claims it breached FBI systems through an unpatched Oracle PeopleSoft zero-day enabling remote code execution, then moved laterally into FBI-managed AWS GovCloud. The group says it stole 2TB to 3TB of data covering current and former FBI employees, applicants, and internal records, and compromised FBI Criminal Justice, HR, and Medlink services. It shared a screenshot of apply.fbijobs.gov defaced with its Umbreon logo. The FBI confirmed it is investigating unauthorized activity affecting FBIjobs.gov but did not confirm a breach or data theft. 404 Media reported receiving roughly 5,000 purported employee records and verified some details. ShinyHunters called the attack retaliation for a May 2026 FBI FLASH report and gave the FBI one week to remove it.
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach →
BigDiskBuster PoC blocks Microsoft Defender updates on Windows
Researcher NightmareEclipse, also known as Abdelhamid Naceri, released a proof-of-concept tool called BigDiskBuster that prevents Microsoft Defender Antivirus from installing platform and security intelligence updates. The tool does not disable Defender; it waits for an update, creates hidden temporary files to consume free disk space, then releases the space once the update fails. It also opens Microsoft’s MRT.exe in a way that restricts other processes’ access. The researcher says the current PoC is buggy and the claim it works on all supported Windows versions is unverified. A screenshot shows error 0x80070643. There is no indication of real-world use, and Microsoft has not responded. The release continues a public dispute over vulnerability disclosure.
NightmareEclipse’s latest zero-day leaves Microsoft Defender stuck in the past →
AI agent frameworks power card-skimming campaign hitting 119 sites
A financially motivated threat actor used open-source AI agent frameworks to attack hundreds of online retailers, stealing more than 600,000 credit card records since at least July. Gambit found the campaign compromised at least 119 websites with skimmers and breached a Fortune 500 hospitality company, a major U.S. airline, a large industrial supplies distributor, and an online fashion retailer. Three tools powered the chain: Strix for scanning, Cairn for autonomous exploitation, and Hermes for orchestration using claude-opus-4.6. Between September 10 and 15, the attacker launched 105 attack waves, succeeding on at least 27. Costs are estimated at $12,000 to $18,000, averaging about $25 per target.
Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers →
F5 patches BIG-IP APM zero-day exploited in RCE attacks
F5 released security updates for a critical BIG-IP APM zero-day, tracked as CVE-2026-94127, exploited in remote code execution attacks. The flaw affects instances configured as an OAuth Authorization Server when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server. F5 warned in a Tuesday advisory that the vulnerability has been exploited. Deployments using APM strictly as an OAuth Client or Resource Server are not affected. CISA added the flaw to its Known Exploited Vulnerabilities Catalog and ordered U.S. federal agencies to secure networks by Friday. Shadowserver tracks over 14,700 IP addresses with BIG-IP APM fingerprints. F5 serves more than 23,000 customers worldwide.
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks →
DHS fusion centers monitored activists building anti-ALPR tech
Department of Homeland Security fusion centers have begun monitoring anti-surveillance activists, according to records obtained by Reason. An intelligence report compiled in Massachusetts and redistributed by a Wisconsin fusion center shows the government tracking online critics of automated license plate readers such as Flock Safety. The report names SparrowMap, a website using ALPR technology to track police vehicles in real time. SparrowMap processes public livestreams and volunteer footage; of 300,000 vehicles picked up daily by its 14,196 cameras, only a few dozen are police vehicles, and the rest is quickly deleted. Founder Matthew Montney Jr. said he built it to give people government transparency. The report cites August 2026 Reddit users encouraging collection of government vehicle data.
Homeland Security is monitoring activists building anti-flock tech →