October 4, 2026
Why this day matters
- Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Lunex Unmasked: A New Information Stealer Deployed Through BYOVD Storm-3168:
- A suspected ShinyHunters member arrested in Jordan is reportedly cooperating with the FBI, helping investigators track down the group.
Enriched source records
Luna-generated claims retained by the evidence and claim-validation gates. Automated validation does not imply human review. A record does not need a CVE to be included.
Luna-enriched source article · the hacker newsChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
TA419, described as a China-nexus cyber espionage group, has been attributed to multiple credential-phishing campaigns targeting AI experts at U.S. think tanks, universities, and legal-sector organizations.
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
TA419, described as a China-nexus cyber espionage group, has been attributed to multiple credential-phishing campaigns targeting AI experts at U.S. think tanks, universities, and legal-sector organizations.
Source published Oct 4, 2026, 7:20 AM UTC · Evidence retrieved Oct 4, 2026, 1:23 PM UTC
What happened
TA419, described as a China-nexus cyber espionage group, has been attributed to multiple credential-phishing campaigns targeting AI experts at U.S. think tanks, universities, and legal-sector organizations. [1] [2]
The campaigns impersonated prominent economists, AI policymakers, and a prominent Anthropic employee to target an AI policy expert. [3]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S.
- [2]
think tanks, universities, and legal sector organizations.
- [3]
The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a
Luna-enriched source article · the hacker newsShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
Reuters reportedly said that Jordanian authorities detained a suspected ShinyHunters digital-extortion-group member known online as “Rey,” citing three people familiar with the matter.
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
Reuters reportedly said that Jordanian authorities detained a suspected ShinyHunters digital-extortion-group member known online as “Rey,” citing three people familiar with the matter.
Source published Oct 4, 2026, 7:22 AM UTC · Evidence retrieved Oct 4, 2026, 1:23 PM UTC
What happened
Reuters reportedly said that Jordanian authorities detained a suspected ShinyHunters digital-extortion-group member known online as “Rey,” citing three people familiar with the matter. [1]
The suspect was identified as Saif al-Din Khader and was reportedly brought into custody on September 29, 2026. [2]
The supplied text states that Khader was cooperating with the U.S. Federal Bureau of Investigation, but the sentence is truncated before explaining the cooperation. [2] [3]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter.
- [2]
Rey, whose real name is Saif al-Din Khader, is said to have been brought into custody on September 29, 2026, cooperating with the U.S.
- [3]
Federal Bureau of Investigation (FBI) and
Luna-enriched source article · securityaffairsWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
Symantec tracks the group behind Warlock ransomware as Longlegs, also known as Storm-2603, and reports that it continues exploiting unpatched SharePoint flaws for initial access.
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
Symantec tracks the group behind Warlock ransomware as Longlegs, also known as Storm-2603, and reports that it continues exploiting unpatched SharePoint flaws for initial access.
Source published Oct 4, 2026, 7:49 AM UTC · Evidence retrieved Oct 4, 2026, 8:51 AM UTC
What happened
Symantec tracks the group behind Warlock ransomware as Longlegs, also known as Storm-2603, and reports that it continues exploiting unpatched SharePoint flaws for initial access. [1] [2] [3] [4]
In the past two months, Longlegs reportedly hit at least four organizations—a water utility, telecom provider, regional government body, and university—in Portuguese- or Spanish-speaking countries. [5] [6]
The intrusion described by Symantec began with a webshell on a SharePoint server, followed by machine-key abuse and a forged signed payload that achieved code execution inside SharePoint. [7] [8] [9] [10]
After gaining access, the attackers used DLL sideloading, downloaded payloads from legitimate hosting services, and abused the signed vulnerable K7RKScan driver to disable security software. [11] [12] [13]
The attackers also installed Visual Studio Code’s tunneling feature as a service, providing remote access that could resemble developer activity. [14]
Why it matters
In one critical-infrastructure intrusion, security-disabling tooling reached at least 40 hosts in about two hours, and Warlock was then deployed on at least 33 hosts through the domain’s SYSVOL share. [15] [16] [17]
The attackers broadened the intrusion from two initial SharePoint servers to additional hosts, including by repeatedly adding the SPSEPRDSetup domain account to local Administrators groups on three hosts. [18] [19]
Known limitations
The report says the recent concentration on Portuguese- and Spanish-speaking countries could reflect opportunistic searching for exposed, unpatched SharePoint servers or deliberate targeting; the evidence does not resolve between those explanations. [20] [21] [22]
Some generated claims did not pass validation and were omitted. Only retained claims are shown.
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Warlock ransomware continues to exploit unpatched SharePoint flaws to breach water utilities, telecoms, governments, and universities worldwide.
- [2]
Symantec tracks the group behind Warlock as Longlegs, also known as Storm-2603 , and ties it back to older China-nexus clusters called CL-CRI-1040, CamoFei, and ChamelGang.
- [3]
SharePoint is still the main entry point.
- [4]
The technique is effective, but it depends on finding SharePoint servers that have not been properly patched.
- [5]
In the past two months alone, Longlegs hit at least four organizations: a water utility, a telecom provider, a regional government body, and a university.
- [6]
All four sit in Portuguese or Spanish speaking countries, spread across Europe, Africa, and Latin America.
- [7]
Longlegs places a webshell in the LAYOUTS directory and designs it to work across different SharePoint versions.
- [8]
The attackers then steal the server’s ASP.NET machine keys and use them to create a signed payload that can execute code inside the SharePoint application.
- [9]
“Longlegs abuses a vulnerable, signed driver (K7RKScan) to disable security software before deploying ransomware, and has also been observed abusing Visual Studio Code’s tunneling feature for covert remote access.” Symantec’s report traces a full attack against a critical infrastructure operator starting July 22, 2026, when the webshell first landed on a SharePoint server.
- [10]
By July 28 the real exploitation began, using a deserialization gadget to turn a forged, signed payload into code execution inside SharePoint.
- [11]
Once they get inside, the attackers use DLL sideloading to run additional payloads.
- [12]
They download these files from legitimate hosting services such as catbox.moe and wasabisys.com, which helps the traffic blend in with normal activity.
- [13]
Before deploying the ransomware, Longlegs also uses a signed but vulnerable driver called K7RKScan to disable security software.
- [14]
The attackers have also installed Visual Studio Code’s tunneling feature as a service, giving them remote access that can look like normal developer activity.
- [15]
On July 31, the attackers deployed a tool designed to disable antivirus and EDR across the network in a short period.
- [16]
“In one intrusion against a critical infrastructure operator, the attackers pushed a tool designed to disable security software to at least 40 hosts within about two hours, then deployed Warlock on at least 33 hosts by staging it in the domain’s SYSVOL share, where ordinary domain replication delivered it to machines.” Symantec states.
- [17]
Warlock ransomware was then deployed almost immediately after the security tools were disabled.
- [18]
“The intrusion then broadened from the two initial SharePoint servers to the wider domain.
- [19]
Later that day and into the next (July 29) the attackers repeatedly added a domain account named SPSEPRDSetup to the local Administrators group on three further hosts (Computer 3, Computer 4, and Computer 5):” They spread out to more hosts by adding a fake-sounding admin account named SPSEPRDSetup, a decent bit of social camouflage since SharePoint really does create accounts with that kind of prefix.
- [20]
The recent attacks on Portuguese- and Spanish-speaking countries could simply mean the attackers are looking for exposed and unpatched SharePoint servers wherever they can find them.
- [21]
They could also be working from a specific target list.
- [22]
“The apparent recent focus on Portuguese- and Spanish-speaking countries suggests either an opportunistic targeting pattern driven by exposed, vulnerable SharePoint servers, or a more deliberate tasking.
Luna-enriched source article · securityaffairsShinyHunters Suspect Detained in Jordan Helps FBI Track Down the Group
A suspected ShinyHunters member, Saif al-Din Khader, was detained in Jordan and is reportedly cooperating with the FBI and international law enforcement.
ShinyHunters Suspect Detained in Jordan Helps FBI Track Down the Group
A suspected ShinyHunters member, Saif al-Din Khader, was detained in Jordan and is reportedly cooperating with the FBI and international law enforcement.
Source published Oct 4, 2026, 1:41 PM UTC · Evidence retrieved Oct 4, 2026, 2:51 PM UTC
What happened
A suspected ShinyHunters member, Saif al-Din Khader, was detained in Jordan and is reportedly cooperating with the FBI and international law enforcement. [1] [2] [3] [4]
One source said Khader was showing investigators his devices and digital communications to help identify former associates. [5]
Reuters could not confirm the exact circumstances of Khader’s arrest or where he was being held. [7]
Reuters lost contact with ShinyHunters’ usual communication account, and the group’s dark-web leak site subsequently went offline; a new leak site reportedly returned later that week. [8] [9]
Why it matters
Reuters reported that a leaked ShinyHunters sample included personal information, sensitive job-related data, and psychiatric and medical records concerning FBI employees. [6]
Known limitations
The FBI declined to comment on any specific arrest or overseas activity, while saying it continues investigating the cyber incident and has worked with partners to arrest multiple subjects. [10]
Interpretation: The supplied evidence supports treating the cooperation and the group’s reported disruption as developments under investigation, not as confirmation that ShinyHunters has ceased operating. [1] [7] [8] [9] [10]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
A suspected ShinyHunters member arrested in Jordan is reportedly cooperating with the FBI, helping investigators track down the group.
- [2]
The man is Saif al-Din Khader, detained by Jordanian authorities, with two sources placing the arrest on Tuesday.
- [3]
“A suspected member of the ShinyHunters hacking group, which says it stole data on every FBI employee, was detained in Jordan this week and is cooperating with the FBI, three people familiar with the matter told Reuters.” the Reuters states .
- [4]
Two sources said he’s now helping the FBI and international law enforcement track down the rest of the group.
- [5]
One source told Reuters that Khader is showing investigators his own devices and digital communications to help identify former associates.
- [6]
ShinyHunters claims to have stolen personal data on FBI employees, and Reuters’ earlier analysis found that the leaked sample included detailed personal information, sensitive job-related data, and psychiatric and medical records.
- [7]
Reuters couldn’t confirm the exact circumstances or where he’s being held.
- [8]
Reuters lost contact with the group’s usual communication account on Tuesday, the same day Khader was reportedly detained, and by Wednesday the group’s dark web leak site had gone offline entirely.
- [9]
A new ShinyHunters leak site reportedly came back online on Thursday, so the group itself isn’t dead, just missing one more member.
- [10]
“The FBI declined to comment on any specific arrest or activity abroad but said that the bureau “continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects — and we will spare no resource in bringing each of the responsible individuals to justice.”” Reuters continues.
Additional source records
Material developmentsUser Agent Strings Curiosities, (Sun, Oct 4th)
Sans Isc Diary published a source item for review.
User Agent Strings Curiosities, (Sun, Oct 4th)
Sans Isc Diary published a source item for review.
What happened
Sans Isc Diary published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- User Agent Strings Curiosities, (Sun, Oct 4th) Sans Isc Diary · Published 2026-10-04T07:58:51Z · Retrieved Oct 4, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117
Securityaffairs published a source item for review.
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117
Securityaffairs published a source item for review.
What happened
Securityaffairs published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117 Securityaffairs · Published 2026-10-04T14:00:02Z · Retrieved Oct 4, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsWeek in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited
Helpnetsecurity published details for CVE-2026-88771, CVE-2026-88772.
Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited
Helpnetsecurity published details for CVE-2026-88771, CVE-2026-88772.
What happened
Helpnetsecurity published details for CVE-2026-88771, CVE-2026-88772.
Why it matters
A reviewed impact interpretation has not been published for this record.
Structured associations
Reviewed next steps
- Check asset inventory and patch status for CVE-2026-88771, CVE-2026-88772.
Evidence
- Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited Helpnetsecurity · Published 2026-10-04T08:00:19Z · Retrieved Oct 4, 2026, 8:51 AM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsSecurity Affairs newsletter Round 598 by Pierluigi Paganini – INTERNATIONAL EDITION
Securityaffairs published details for CVE-2026-90970.
Security Affairs newsletter Round 598 by Pierluigi Paganini – INTERNATIONAL EDITION
Securityaffairs published details for CVE-2026-90970.
What happened
Securityaffairs published details for CVE-2026-90970.
Why it matters
A reviewed impact interpretation has not been published for this record.
Structured associations
Reviewed next steps
- Check asset inventory and patch status for CVE-2026-90970.
Evidence
- Security Affairs newsletter Round 598 by Pierluigi Paganini – INTERNATIONAL EDITION Securityaffairs · Published 2026-10-04T07:58:06Z · Retrieved Oct 4, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
AI and model realityAnthropic asks Claude users to share voice data for AI model training
Bleepingcomputer published a source item for review.
Anthropic asks Claude users to share voice data for AI model training
Bleepingcomputer published a source item for review.
What happened
Bleepingcomputer published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Anthropic asks Claude users to share voice data for AI model training Bleepingcomputer · Published 2026-10-04T10:53:21Z · Retrieved Oct 4, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.