Security Digest

[Cybersecurity Digest] ShinyHunters just breached the FBI

Sent · Cybersecurity & Privacy Digest

A PeopleSoft zero-day, chained Chrome exploits, and 5,700 hijacked Microsoft accounts. That is this week in cybersecurity, and none of it involves anything you have not heard of before, which is exactly the problem.


The Big 3

ShinyHunters says it just hacked the FBI

On 22 September, extortion group ShinyHunters claimed it broke into FBI systems through a previously unknown flaw in Oracle PeopleSoft, walking off with 2 to 3TB of data including records on almost all Bureau agents and job applicants. The group defaced the FBI careers portal, FBIjobs.gov, with a fake seizure notice. The FBI confirmed it is investigating but has not verified the claims.

Why it matters: This is the same crew the FBI publicly warned about in May, and the timing looks a lot like payback, which tells you these groups now treat law enforcement statements as a target list, not a deterrent.

Read more at The Hacker News

Chinese hackers were chaining Chrome and Windows zero-days for weeks

Volexity found at least two separate Chinese state-linked groups using fake websites to deliver chained exploits combining Chrome V8 bugs (CVE-2026-85046, CVE-2026-87491) with a Windows flaw, letting them break out of the browser sandbox entirely. One campaign was running while the Chrome bug was still unpatched.

Why it matters: Update Chrome and Windows now if you have not. Sandbox escapes chained through fake sites turn clicking a link into a full device compromise.

Read more at Volexity

5,700 Microsoft 365 accounts hit by one automated tool

Researchers have been tracking UNK_CondorFiltration, a campaign using the open-source TeamFiltration framework to hammer Microsoft 365 tenants with credential stuffing and session hijacking, hitting more than 5,700 accounts across 28 organisations.

Why it matters: If your business runs on Microsoft 365, check sign-in logs for unfamiliar locations and turn on conditional access. This is not a sophisticated nation-state operation, it is a free tool doing damage because basic MFA hygiene is not there yet.

Read more at The Hacker News


Quick Hits

Settra ransomware is breaking into retail and manufacturing firms through stolen VPN credentials, no phishing required, according to Huntress.

Metaencryptor ransomware hit a South Korean camera module maker and a Japanese auto parts supplier this week, both through unpatched edge devices.

NightmareStresser, a DDoS-for-hire service running since 2022, is shut down, its operator ordered to pay 1.2 million dollars to victims.

BragJack abuses a Chrome extension API to hijack AI agent browsing sessions, redirecting them without the user noticing, a preview of what AI-agent security holes look like.


Tool of the Week

YubiKey 5 NFC is a hardware security key that gives you phishing-resistant two-factor authentication on accounts that support it. For anyone whose employer runs Microsoft 365 (see story three), this is the cheapest fix for account takeover that actually works.

YubiKey 5 NFC on Amazon


Protect Yourself

If you or your work uses Microsoft 365, check your sign-in activity this week. Go to myaccount.microsoft.com, then Sign-in activity, and look for locations or devices you do not recognise. Revoke anything odd. Given over 5,700 accounts have been hit by one automated tool this month, this two minute check is worth doing today, wherever you are.


Forwarded this? Get your own cybersecurity briefing at futuretechnologyhq.com/newsletter

Stay safe out there. Nath, Future Technology

Some links in this newsletter may be affiliate links. We only recommend products we genuinely think are worth your time.

← Back to the archive

Get the briefing

The biggest tech story, explained in 3 minutes. Delivered free every weekday.

Trusted by thousands of readers