ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
2026-09-23T07:24:00Z•ed2e28943c5c9678d505d04fd3642efa1b467a7f498316e1e3421f7976e6cecf
CVE-2026-65660CVE-2026-7273CVE-2026-89775CVE-2026-90898CVE-2026-93485CVE-2026-93616CVE-2026-93952AI securityCISA KEVCheck PointEDR evasionLinux kernelMicrosoft SharePointNorth KoreaPowerShellSideCopyVeloCloudWordPressactive exploitationcredential theftdata breachmalwarenpm supply chainphishingprivilege escalationremote code executionunauthenticated RCEvirtualization escapezero-day
What happened
A September 2026 cybersecurity news feed reports multiple high-impact threats, including actively exploited and zero-day vulnerabilities, unauthenticated remote code execution, cloud and virtualization escapes, supply-chain malware, phishing services, ransomware/extortion claims, and targeted campaigns. Notable issues include Check Point Security Management Server RCE, critical Bifrost AI gateway RCE (CVE-2026-90898), VeloCloud Orchestrator flaw (CVE-2026-93952), ARM64 KVM host-memory access (CVE-2026-89775), SharePoint authenticated RCE (CVE-2026-65660), WordPress Comment2Shell (CVE-2026-934ด
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- ed2e28943c5c9678d505d04fd3642efa1b467a7f498316e1e3421f7976e6cecf
- Enrichment time
- 2026-09-23T07:24:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.