Security
FBI breach exposes data on agents in China and Russia units
FBI assesses ShinyHunters breach of applicant portal, Pentagon confirms 2.76M records exposed, and an unpatched Windows 0day surfaces.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
FBI still assessing ShinyHunters breach of job applicant portal
A week after ShinyHunters claimed to steal sensitive data on thousands of current and former FBI employees, the bureau is still assessing damage and facing internal criticism. Hackers breached an online portal hosting information on FBI job applicants, taking Social Security numbers, emergency contacts and home addresses, including data on personnel in sensitive China and Russia units. The group demanded the FBI amend an advisory describing its extortion tactics, which many read as a threat to leak. The FBI said potentially impacted employees were notified repeatedly, including Saturday, and that it is operating on the assumption hackers stole data on all employees. Some agents worry public home addresses could endanger families.
FBI grapples with fallout from massive data breach →
Pentagon breach exposed data on nearly 3 million people
A breach of a Defense Manpower Data Center information system exposed personally identifiable information on 2.76 million living people and another 294,000 deceased individuals, including Social Security numbers and job details, a U.S. defense official said. A small number of unauthorized users had access between October 2025 and July 2026. Upon discovery, DMDC immediately remediated the vulnerability and patched the affected system. The center is one of the Pentagon’s main personnel record repositories, holding more than 60 million records covering troops, civilians, contractors, retirees, veterans and family members. Military Times first reported the breach. There is no evidence yet of misuse, and identity protection and credit monitoring are being offered.
Pentagon breach exposed sensitive data on nearly 3 million people →
Remote code execution flaw found in OpenCode AI coding agent
Datadog Security Labs discovered GHSA-632h-h47v-g4x4, a remote code execution vulnerability in OpenCode, the open-source AI coding agent from Anomaly with over 200,000 GitHub stars and 16 million monthly users. A content-type confusion in the /global/upgrade endpoint made a code injection flaw exploitable, letting an attacker supply an arbitrary npm tarball URL that executes a preinstall script when a victim visits a malicious webpage. Versions 1.14.30 through 1.18.21 installed via npm, pnpm or Bun are affected; those 82 versions saw more than 647,000 downloads from September 17 to 23, 2026. OpenCode 1.18.22 fixes it. Anomaly declined to request a CVE.
Unpatched Windows NCSI flaw enables privilege escalation via proxy coercion
A vulnerability in the Windows Network Connectivity Status Indicator allows local privilege escalation through proxy authentication coercion. When a low-privileged user modifies proxy settings, NCSI runs a WinHTTP probe as the machine account and fails to disable NTLM, handing machine credentials to any proxy demanding authentication. In a penetration test, an attacker pointed the user proxy at a local ntlmrelayx listener, relayed the MACHINE$ authentication to an AD CS Web Enrollment endpoint lacking EPA and HTTPS, enrolled a certificate, obtained a Ticket Granting Ticket, forged a Silver Ticket with Domain Admins SID and executed code via WMI. Microsoft declined a CVE; ZDI published it as ZDI-26-708. Mitigations include enforcing EPA and HTTPS on AD CS endpoints.
Escalating Windows Privileges: Exploiting NCSI Vulnerabilities →
Proton Mail sender spoofing remains unfixed after bounty dispute
Proton Mail’s web interface can present a forged sender identity visually indistinguishable from a legitimate one, combining three weaknesses. Display-name text appears where users read the sender address, and the default system font renders capital I and lowercase l identically, so gmaiI.com looks like gmail.com. Messages from domains without a DMARC record get no authentication-failure banner, and a Reply-To alias can route replies to an attacker. The finding was demonstrated against the reporter’s own accounts using swaks over Proton’s inbound MX. Reported in February 2025 and bounty-awarded in April 2025, no fix shipped; the issue still reproduced as of September 2026, and Proton later said it did not qualify for the bug bounty program.
Sender spoofing in Proton Mail via display-name homograph | protonmail-sender-spoofing →