The FBI is investigating ShinyHunters’ claims that the group exploited a previously unknown bug on FBIJobs.gov and stole personal data belonging to thousands of current and former employees. The reported incident involved taking down FBIJobs.gov and posting a banner claiming the site had been seized; ShinyHunters told The New York Times that approximately two to three terabytes of data were taken.
Why it matters
The data reportedly included names, home addresses, phone numbers, spouses’ names, certain medical information and other information concerning current and former agents and applicants.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily
Identity · Certcc Vulnotes
What happened
Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform, contains CVE-2026-82356 in versions 26.2.6 and below because it lacks a supported mechanism to rotate the RSA key pair used to generate the appliance’s X.509 certificate. The advisory states that the vendor is aware of the issue and reportedly working toward a resolution, but no fix or timeline had been provided at publication.
Why it matters
If an attacker obtains the private key through backup exfiltration, a hypervisor snapshot, or privileged filesystem access, they can impersonate the trusted appliance to endpoints that rely on it for authentication.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily
Exploitation · Cyberscoop
What happened
The article reports that state and local governments overseeing critical resources are routinely targeted by state-backed actors, while many lack sufficient cybersecurity budgets and staffing. CISA issued a joint advisory describing an active threat against Siemens S7 programmable logic controllers, which control industrial equipment including valves, motors, and pumps.
Why it matters
The Center for Internet Security reportedly found that about one-third of surveyed local agencies conducted minimal or no cybersecurity activities.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Evidence is visible. Uncertainty stays visible too.
Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.