ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

2026-09-23T07:24:00Z•ed2e28943c5c9678d505d04fd3642efa1b467a7f498316e1e3421f7976e6cecf
CVE-2026-65660CVE-2026-7273CVE-2026-89775CVE-2026-90898CVE-2026-93485CVE-2026-93616CVE-2026-93952AI securityCISA KEVCheck PointEDR evasionLinux kernelMicrosoft SharePointNorth KoreaPowerShellSideCopyVeloCloudWordPressactive exploitationcredential theftdata breachmalwarenpm supply chainphishingprivilege escalationremote code executionunauthenticated RCEvirtualization escapezero-day

What happened

A September 2026 cybersecurity news feed reports multiple high-impact threats, including actively exploited and zero-day vulnerabilities, unauthenticated remote code execution, cloud and virtualization escapes, supply-chain malware, phishing services, ransomware/extortion claims, and targeted campaigns. Notable issues include Check Point Security Management Server RCE, critical Bifrost AI gateway RCE (CVE-2026-90898), VeloCloud Orchestrator flaw (CVE-2026-93952), ARM64 KVM host-memory access (CVE-2026-89775), SharePoint authenticated RCE (CVE-2026-65660), WordPress Comment2Shell (CVE-2026-934ด

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
ed2e28943c5c9678d505d04fd3642efa1b467a7f498316e1e3421f7976e6cecf
Enrichment time
2026-09-23T07:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.