2026-10-09 18:45 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-09 19:50 UTC
Japan helped extradite a Russian suspect linked to Qilin ransomware to Germany, but the gang continued attacking victims after his arrest. Germany has arrested a Russian national believed to be a leading figure in the Qilin ransomware group, and Japan’s National Police Agency just put its own role in that arrest on the record. The […]
P15
2026-10-09 17:45 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 19:00 UTC
The FBI has arrested another suspected co-conspirator of ShinyHunters, FBI Director Kash Patel said on October 9 in a post on X. ShinyHunters is the extortion group that said in September it had breached the FBI's jobs portal and stolen sensitive data on almost all FBI agents and job applicants. The FBI has not named the suspect, and no charges have been made public. The
P0
2026-10-09 17:21 UTC
Security Journalism
Dark Reading · Rob Wright, Alexander Culafi · indexed 2026-10-09 17:35 UTC
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the arrest of a suspected ShinyHunters operative to the compromise of a Pentagon-run data center.
P0
2026-10-09 17:02 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-10-09 17:15 UTC
The FBI has arrested another suspected member of the ShinyHunters extortion group believed to be involved in the recent breach of FBI systems, Director Kash Patel announced Friday. [...]
P0
2026-10-09 15:41 UTC
Security Journalism
The Record · indexed 2026-10-09 15:50 UTC
“We will continue to work closely with our partners to disrupt what’s left of the ShinyHunters group and their associates, no matter where they operate," FBI Director Kash Patel said.
P0
2026-10-09 15:38 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-09 15:45 UTC
Germany has arrested a Russian national suspected of being a leading member of the Qilin ransomware group following extradition from Japan earlier this month. [...]
P15
2026-10-09 14:52 UTC
Vendor Research
Tenable Research Advisories · Joshua Martinelle · indexed 2026-10-09 15:25 UTC
WordPress - Post Author Second Order SQLi A regression was introduced in version 4.0.0 of WP Post Author, the multi-authors module stores the co-author list in the wpma_author post meta and later interpolates each stored value directly into a SQL query. Neither end of that path is safe.On write, awpa_ma_save_metabox() takes $_POST['wpma_metabox_authors_list'], splits it on commas, and stores each element verbatim. The handler computes a sanitized copy and then stores the raw value instead:// in…
P0
2026-10-09 10:49 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-09 10:50 UTC
DOJ and FBI seized China-linked hacking tools Microscan and FishHub, linked to Integrity Tech and attacks on critical infrastructure worldwide. The Justice Department and FBI took down two hacking tools this week, Microscan and FishHub, both built and run by a Beijing-based company with direct government contracts. The tools were used to scan, and in […]
P0
2026-10-09 06:39 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 06:55 UTC
The U.S. Federal Bureau of Investigation (FBI) and Department of Justice (DoJ) have announced the disruption of malicious tools used by a China-linked advanced persistent threat group known as Flax Typhoon. To that end, the agencies seized several domains and blocked access to platforms that were used to scan, and in some cases infiltrate, U.S. critical infrastructure. The list of seized
P0
2026-10-08 21:42 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-10-08 21:45 UTC
The FBI has seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, used in attacks that breached critical infrastructure and other organizations worldwide. [...]
P0
2026-10-08 19:08 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-10-08 19:25 UTC
The first cybercriminal to ever make the FBI's "10 Most Wanted Fugitives" list allegedly infused Tren de Aragua's violent criminal operations with cash.
P0
2026-10-08 18:32 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 18:55 UTC
Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8. The company, Integrity Technology Group, has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws using a tool containing more
P0
2026-10-08 17:00 UTC
Security Journalism
The Record · indexed 2026-10-08 17:15 UTC
The owner of a ransomware recovery firm was hit with wire fraud charges for allegedly making secret ransom payments while overcharging the victims of attacks.
P15
2026-10-08 07:41 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 08:10 UTC
The U.S. Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S. and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while claiming to use proprietary tools to recover their data. Zohar Pinhasi (aka Zack Silver and Zack Green) has been charged with two counts of wire fraud and one count of wire
P15
2026-10-07 21:28 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-07 21:35 UTC
The FBI is warning that FortiBleed attacks are still ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators. [...]
P0
2026-10-07 13:49 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-07 14:30 UTC
FBI and Secret Service warn FortiBleed, a credential-harvesting campaign against Fortinet firewalls, has compromised 86,644 devices and is locking out admins. The FBI and the U.S. Secret Service issued a joint advisory about FortiBleed, and the headline number alone is worth sitting with: more than 86,644 compromised Fortinet FortiGate devices across 194 countries, according to […]
P0
2026-10-07 13:48 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-10-07 13:55 UTC
A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle "Rey," was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing, which manufactures the fleet of planes used by the employer of Rey's…
P0
2026-10-07 13:47 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-07 13:50 UTC
The individual was detained in May and has been extradited to Germany to face hacking charges. The post Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany appeared first on SecurityWeek.
P15
2026-10-07 12:50 UTC
Security Journalism
The Record · indexed 2026-10-07 13:10 UTC
Users of two types of Fortinet hardware should take steps to limit their exposure to a now-global credential stealing campaign, U.S. federal law enforcement says.
P0
2026-10-07 11:56 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 12:20 UTC
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat
P0
2026-10-06 15:53 UTC
Security Journalism
The Record · indexed 2026-10-06 16:05 UTC
Aguirre was added to the FBI’s “Top 10 Most Wanted Fugitives” list in March, becoming the first cybercriminal added to the list.
P0
2026-10-06 14:15 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-06 14:20 UTC
The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees. The post FBI Blames Contractor’s Missed Patch for ShinyHunters Breach appeared first on SecurityWeek.
P0
2026-10-06 12:47 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-06 13:00 UTC
An alleged leader of Tren de Aragua’s ATM jackpotting activities, Canelon Aguirre was on the FBI’s top 10 most wanted list since March 2026. The post FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware appeared first on SecurityWeek.
P0
2026-10-06 09:27 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-06 09:40 UTC
Accenture lost an FBI contract after a missed security patch exposed sensitive employee data, raising serious concerns over operational security. The FBI pulled an Accenture contractor off its account on Monday, and the reason is almost mundane compared to the damage it caused. One update didn’t get installed on time. “The Federal Bureau of Investigation […]
P0
2026-10-06 06:56 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 07:40 UTC
The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's according to a report from Reuters, citing two sources familiar with the matter. "To date, our review has determined that the incident occurred as the result of a security failure
P0
2026-10-05 19:15 UTC
Security Journalism
The Record · indexed 2026-10-05 19:30 UTC
Saif al-Din Khader is cooperating with the FBI, reports said, as the bureau responds to a massive breach that exposed employee data.
P0
2026-10-05 13:01 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-05 13:05 UTC
The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus malware, used to steal millions of dollars in ATM jackpotting attacks across the United States. [...]
P0
2026-10-05 08:33 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-05 09:20 UTC
Iranian hacker Amir Barati faces extradition to the US over an alleged Iranian campaign that stole 31TB of data from universities. Amir Barati spent June 25 getting arrested in Montenegro, and this week a Montenegrin court signed off on sending him to the United States. He’s a dual Turkish and Iranian citizen, 40 years old, […]
P0
2026-10-05 07:16 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-05 07:30 UTC
Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group. The post Alleged ShinyHunters Leader Arrested in Jordan appeared first on SecurityWeek.
P0
2026-10-04 13:41 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-04 14:35 UTC
A suspected ShinyHunters member arrested in Jordan is reportedly cooperating with the FBI, helping investigators track down the group. A suspected member of ShinyHunters, the group that claims to have stolen data on every FBI employee, was picked up in Jordan this week. The man is Saif al-Din Khader, detained by Jordanian authorities, with two […]
P0