Article Read Time

1. Extortion Group Claims It Stole Personnel Records on Every FBI Employee
The hacking group ShinyHunters says it used a zero-day vulnerability in Oracle PeopleSoft to reach FBI-linked systems, then pivoted into connected AWS infrastructure to pull an estimated two to three terabytes of data. The group claims the haul includes names, home addresses, phone numbers, dates of birth, and spouse information for FBI employees and applicants nationwide, and a sample reviewed by journalists appears to check out. Investigators and outside researchers warn the exposure could put agents and their families at risk of intimidation or targeting by hostile foreign services.
Source: 404 Media URL: https://www.404media.co/we-hacked-the-fbi-hackers-say-they-have-data-on-all-fbi-employees/
2. New Ransomware Group n0n Threatens to Destroy Backups Rather Than Just Encrypt Them
Researchers at CyberXTron spotted the new ransomware operation n0n on September 18, and within days it had a Tor leak site listing more than a dozen victims. n0n’s stated strategy is to threaten destruction of backups and shadow copies alongside data theft, an escalation designed to strip organizations of any recovery path that does not run through paying the ransom. Financial services firms account for close to a quarter of the group’s claimed victims so far, with initial access typically gained through credentials harvested by infostealer malware.
Source: SC Media URL: https://www.scworld.com/brief/new-ransomware-group-n0n-escalates-threats-by-targeting-backups
3. Attackers Weaponized a Critical WordPress Flaw Within Hours of Its Disclosure
A critical WordPress vulnerability tracked as CVE-2026-87902, rated 9.2 on the CVSS scale, was already being probed against honeypot networks within hours of its public disclosure. The flaw lets an unauthenticated attacker achieve remote code execution by manipulating theme configuration to include malicious files and write PHP payloads directly to disk. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and gave federal agencies until September 28 to patch, and every WordPress administrator running an affected version should treat that same deadline as their own.
Source: The Hacker News URL: https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html
4. Anthropic Details How Threat Actors Are Weaponizing AI Models for Cyber Operations
Anthropic published a threat intelligence report describing several campaigns it disrupted between December 2025 and August 2026, in which state-sponsored groups, financially motivated criminals, and hacktivists used its Claude models to automate reconnaissance, exploitation, data exfiltration, and malware development. The report concludes that AI has changed the economics of intrusion work, letting a single operator or a small crew run multi-victim campaigns that once required a much larger team. Anthropic frames the findings as evidence that AI providers now carry a direct role in disrupting cybercrime at its source, alongside network defenders and law enforcement.
Source: Anthropic URL: https://www.anthropic.com/threat-intelligence-report-september-2026
5. CISA Rolls Out Election Security Plan Ahead of the 2026 Midterms
CISA released new guidance to help state and local election officials harden voter registration databases, voting machines, and election management systems ahead of November’s midterm elections. The agency is offering free services to jurisdictions that request them, including penetration testing, vulnerability scanning, and threat intelligence sharing. The plan arrives with a plain warning attached: election infrastructure remains an attractive target for both criminal and state-sponsored actors as the vote approaches.
Source: Infosecurity Magazine URL: https://www.infosecurity-magazine.com/news/cisa-election-security-midterms/
