this week in security — september 27 2026 edition
THIS WEEK, TL;DR
ShinyHunters hacked FBI's jobs site, exposing personal data of agents and applicants
404 Media ($): The hacking group called ShinyHunters say they hacked into and defaced the FBI's job site and stole reams of data on "almost all" agents, employees, and applicants, including their personal information, as well as some medical data, like blood and urine samples, and psychiatric records, which reporters have verified. The hackers say the breach, linked to a hack of an FBI-run Oracle PeopleSoft server, is not financially motivated but rather to demand that the bureau pulls an earlier public report about the hackers that they say is misleading and mischaracterizes their work. As data breaches go, this one's pretty big and bad, as it's a major counterintelligence risk to thousands of federal and security cleared staffers, amid fears that an adversarial nation could acquire the data — similar to how China hacked the U.S. government's HR department, OPM, back in 2015. Expect more to come from this, including more fallout and investigations. The FBI hasn't publicly confirmed a breach but said it is investigating. It's now been declared a "major incident," prompting a legally required notice to Congress. I still can't believe this very hack was predicted months ago...
More: 404 Media ($) | Reuters ($) | Bloomberg ($) | The Register | DataBreaches.net | BBC News | Bleeping Computer | Ars Technica | Mandiant

OpenAI admits its AI agents hacked and meddled with some government websites
Australia's ABC: OpenAI is back in hot water after the Australian prime minister Anthony Albanese used a press conference on the sidelines of the U.N. General Assembly to announce that one of the AI maker's models hacked an Aussie government website earlier in the year to grab aggregate health statistics, and more data. Albanese was clearly naffed off about the incident, in part because it took OpenAI months to alert the Aussies, as much as it also took the Aussies months to become aware of the incidents. This week also saw the news that the OpenAI models also "meddled" with several U.S. government websites by trying to log in with publicly exposed credentials, which OpenAI says weren't strictly speaking hacks, but in any case were models still acting outside of their supposed guardrails. All of this happened before the Hugging Face breach, so the models' guardrails have allegedly improved — but OpenAI said Saturday that it has since paused training on its more advanced models until it has (presumably even more) "additional safeguards" can be put in place. For its part, Australia is looking into whether OpenAI broke the law as part of the breach. AI giants are said to be now investigating potentially tens of thousands of cases where their models escaped their guardrails.
More: TechCrunch ($) | The New York Times ($) | Wall Street Journal ($) | NBC News ($) | CBS News | Transformer | Associated Press | Sky News | Axios
North Koreans suspected of Bitget hack of $351 million in crypto, a record this year
TechCrunch ($): Crypto exchange Bitget is the latest company to fall victim to a crypto heist linked to North Korean hackers in recent months. The company confirmed this week that the suspected North Korean hackers stole $351 million in crypto from its hot wallet, which is connected to the internet and used for trading, but the theft may be as high as ~$390 million in assets. It's the largest known theft of crypto (so far!) this year, after an earlier massive $320 million heist at Liquid Networks. North Korea remains a major source of crypto thefts to fund its sanctioned nuclear weapons program. Details of the Bitget breach are still unclear, but the exchange has paused withdrawals for now. (Disclosure: I wrote this story!)
More: Bloomberg ($) | Financial Times ($) | Forbes ($) | Fortune ($) | Cointelegraph | CNBC | Hayden Mckenzie | @bitget

Kiteworks urges customers to shut down servers ahead of 'imminent' hack threat
Heise: Kiteworks (formerly Accellion) has alerted its customers to an "imminent" threat targeting its customers as soon as this weekend (aka right now!), per a notification first shared with German news giant Heise. Kiteworks' CISO said that federal authorities told the company it was facing a hacking threat, likely from a zero-day bug that it wasn't aware of, but didn't share more details. This wouldn't be the first time that Kiteworks, which produces file transfer software for companies to share large datasets over the internet, has been targeted by hackers, after its customers' file transfer tools were mass-hacked in 2021 by the Clop extortion gang. If you haven't shut down your server already, you might want to get on that as soon as possible. Also, breaking this weekend! At least two new Citrix NetScaler zero-days are reportedly under attack, per @watchTowr, with researchers urging similar customer server shutdowns. IFIN has more for you.
More: TechCrunch ($) | CyberWire ($) | ComputerWeekly | The Record | SC Media | Bleeping Computer
~ ~
~this week in security~ is my weekly cybersecurity newsletter supported by readers like you. Please consider signing up for a paying subscription starting at $10/month for access to exclusive articles, analysis, and more.
You can also submit a one-time tip to show your support, or consider gifting a paid subscription.
Recent blogs: Watch what you say: Apple opens the door to a nightmare world of always-listening tech | Vigilantism comes for Flock | A breach of over 150 million U.S. and Canadian driver's license photos is an anonymity disaster
~ ~
THE STUFF YOU MIGHT'VE MISSED
DOJ accuses phone hacking company of hiding Russian ownership
Kim Zetter's Zero Day: U.S. prosecutors have charged two executives, including the CEO, at tech company Oxygen Forensics, which makes forensic and phone unlocking tech for American police and federal agencies. Prosecutors accuse the two of conspiracy to commit wire fraud after allegedly lying about the true ownership of the company — allegedly Russian — and where its technology is developed. More from Cyberscoop.
Manchester City guilty after hacker exposed reams of financial documents
BBC Sport: Read the wild backstory of Rui Pinto, a computer hacker and whistleblower who is behind the Football Leaks, a huge cache of documents and files relating to Manchester City Football Club, including sponsorship deals and payments. This week, the Premier League found the club guilty of the majority of charges relating to financial rule breaches exposed by the files. The BBC looks at his story and the controversies of Pinto's disclosures, and how fans are perceiving him. (Admittedly, I missed this story over the years — as a Brit who doesn't follow football; I know, I'm terrible — but this is a pretty decent piece to get you up-to-date.) Also check out this blast-from-the-past from Columbia Journalism Review in 2019 on Pinto's case.
Meta's new Muse AI assistant had a major zero-day bug
Ars Technica: Meta's Muse AI assistant, which requires unbridled access to your computer to "help" (heavy air-quotes) you do things, was released earlier this month and is already facing questions about its security. @patrickwardle found a bug that allowed local apps to gain complete control of the user's AI agent by stealing its authentication token. It's a reminder that AI and other apps, which require broad access to your system, can be bad for your security and privacy if compromised. Meta has fixed the bug.
ShinyHunters said it hacked and defaced Clop extortion gang's site
Bank Info Security: In other Hacker Drama™, the ShinyHunters hackers said it hacked the Clop extortion gang's dark web leak site, defaced it, and stole its victims' data. The hackers are demanding a ransom from Clop. It's not clear why Shiny hacked Clop. But, there was a brief overlap between some of Shiny's current members who were previously part of an earlier coalition of hacker groups known as Scattered Lapsus$ Hunters, which somehow leaked exploit code that Clop used to hack Oracle EBusiness users. All to say, expect more hacker infighting to come.

HarmBlock child safety phone is riddled with security flaws and exposed kids' locations
Paul Moore: You know that look when someone winces so hard their face scrunches up in agony at what they've just seen, enter the latest blog by Paul Moore, whose latest security findings will frustrate you from start to finish. This was excellent work uncovering how a child safety phone called HarmBlock is vulnerable to very basic and easy-to-exploit security flaws that will make you want to scream into the void for the rest of time.
Supabase customers are publicly exposing their users' data
UpGuard: A mass-scan across database hosting giant Supabase found that thousands of customers are exposing users' private data, including names, addresses, phone numbers, and in some cases more sensitive data, like authentication tokens for logging into people's accounts. This is often because of misconfigurations by Supabase customers themselves. Some of the databases included popular apps and services exposed data, including an African consulate, an immigration and relocation service, and an Indian adult streaming site. I wrote some words for TechCrunch ($) (disclosure alert!).
~ ~
OTHER NEWSY NUGGETS
House recess nukes cyber bills: Several cybersecurity-related bills in the U.S. Congress failed almost immediately after House Speaker Mike Johnson sent lawmakers home until November to prevent lawmakers from impeaching the U.S. Secretary of Defense for alleged war crimes. With the House now in recess, states are unlikely to get grant money for cybersecurity, and those AI security and kill-switch bills are now on ice, too. (via Politico ($), The Hill ($))
Google fined for flubbing location data: Irish authorities fined search and advertising giant Google some $463 million this week for breaching European data protection rules years ago after mishandling people's location data. (via ABC News, Engadget)
Fresh worry for water works: Water and wastewater providers around the U.S. have a new worry: malware capable of grabbing passwords and letting hackers log into critical systems. SpyCloud found over 1,700 logins exposed across 10,000 organizations registered with the U.S. Environmental Protection Agency, including one centralized vendor that had access to over 160 different organizations' systems. This is on top of the recent rash of Iran-linked hacks targeting over a hundred U.S. water providers. Cyberscoop has more words on the dual threat.
Wired's women in tech survey: Wired ($) surveyed hundreds of women to understand the state of tech today as compared to around five years ago. The results are pretty interesting and worth your time to read. About half of those surveyed say that the tech industry is unchanged or worse for women since 2020.

Congress plans support for cyber-staffers: Lawmakers are seeking fresh support for cyber staffers in the wake of several deaths in U.S. Cyber Command personnel, per reporting by Bloomberg ($). It's unlikely to see anything come to pass until late November or early December until after the U.S. mid-term elections. (via The Record, Tech Times)
Russia's hybrid war set to intensify: Danish intelligence said [PDF] it expects Russia's ongoing hybrid war against the West and NATO to continue, including cyberattacks and sabotage targeting critical infrastructure, aimed at sparking fear and panic. Denmark says the risk of Russian invasion targeting a NATO country is low, if not unlikely, but Russia will continue to stress-test the alliance of countries, especially if the U.S. craps out altogether. The U.K. said it will soon brief critical infrastructure and defense companies to help stay ahead of the ongoing threat from Russia. (via Reuters ($), ABC News, BBC News)
WebRezPro investigating breach: Hotel management software maker WebRezPro, used by hotels across North America, is investigating a possible incident after customers reported receiving WhatsApp messages regarding their reservations. The company is experiencing "intermittent slowness and downtime," and several hotels have notified their customers. (via WebRezPro, Reddit, Hacker News)
~ ~
THE HAPPY CORNER
And not a moment sooner… Welcome back to the Happy Corner! Or, if you're one of the cohort who reads the newsletter bottom-to-top, welcome to your start of the newsletter.

If you needed a tongue-in-cheek laugh at the state of surveillance on campus today, check out how MIT students and staff are responding to the rollout of millions of dollars worth of new AI-powered surveillance cameras… with a brand new "arts initiative." And the results are absolutely fabulous. Some might even say, beautiful?

Flock, the beleaguered surveillance camera maker, is trying to take down the most detailed map to date with all of the locations of its license plate and people-tracking cameras. Flock especially doesn't want you to go to this website and hit the "download full zip" button at the bottom of the page. Don't do that, and certainly don't keep a copy or share it with others.
Major congrats to Firewalls Don't Stop Dragons for its 500th episode, featuring the very excellent Bruce Schneier. The latest episode drops tomorrow.
And, lastly, this week. A bonus cyber-cat this week from my newsletter editor, who barely lifts a finger paw. All typos are courtesy of Toby's unwillingness to proofread.
Have good news to share? Get in touch! this@weekinsecurity.com.
~ ~
CYBER CATS & FRIENDS
This is Euclid, this week's cyber-cat, who is just taking a quick look over your latest security assessment… it says here you're using a password manager, you've two-factored all the things… and you're using an ad-blocker. That's top marks! Thanks so much to Ingrid S. for sending in.

🐈 Keep sending in your cyber cats! 🐈⬛ Thanks to everyone who sends in! If you want your cyber-cat (or friend) featured in an upcoming newsletter, drop me an email with a photo and name of your cat (or non-feline friend).
~ ~
SUGGESTION BOX
That's it after a busy week scouring the news — and up-to-the-minute with some late, breaking additions! Thanks so much for reading, subscribing (and sharing!) this newsletter, it means the world. If you want to support this newsletter as a paid subscriber, head on over this way — and you get full access to the blog and articles as well.
As always, please get in touch if you have anything you want to share for next week's newsletter, from news to research to cool new tech and projects — if you're interested in it, you can bet that someone else is, too!
For those like me on the U.S. east coast, hope you're staying dry and warm amid this Nor'easter weather hitting us. It's a better day than ever to stay inside, brew some coffee, tinker with some tech, or enjoy a long-read or two.
Catch you next week,
@zackwhittaker