[Cybersecurity Digest] ShinyHunters just breached the FBI
A PeopleSoft zero-day, chained Chrome exploits, and 5,700 hijacked Microsoft accounts. That is this week in cybersecurity, and none of it involves anything you have not heard of before, which is exactly the problem.
The Big 3
ShinyHunters says it just hacked the FBI
On 22 September, extortion group ShinyHunters claimed it broke into FBI systems through a previously unknown flaw in Oracle PeopleSoft, walking off with 2 to 3TB of data including records on almost all Bureau agents and job applicants. The group defaced the FBI careers portal, FBIjobs.gov, with a fake seizure notice. The FBI confirmed it is investigating but has not verified the claims.
Why it matters: This is the same crew the FBI publicly warned about in May, and the timing looks a lot like payback, which tells you these groups now treat law enforcement statements as a target list, not a deterrent.
Chinese hackers were chaining Chrome and Windows zero-days for weeks
Volexity found at least two separate Chinese state-linked groups using fake websites to deliver chained exploits combining Chrome V8 bugs (CVE-2026-85046, CVE-2026-87491) with a Windows flaw, letting them break out of the browser sandbox entirely. One campaign was running while the Chrome bug was still unpatched.
Why it matters: Update Chrome and Windows now if you have not. Sandbox escapes chained through fake sites turn clicking a link into a full device compromise.
5,700 Microsoft 365 accounts hit by one automated tool
Researchers have been tracking UNK_CondorFiltration, a campaign using the open-source TeamFiltration framework to hammer Microsoft 365 tenants with credential stuffing and session hijacking, hitting more than 5,700 accounts across 28 organisations.
Why it matters: If your business runs on Microsoft 365, check sign-in logs for unfamiliar locations and turn on conditional access. This is not a sophisticated nation-state operation, it is a free tool doing damage because basic MFA hygiene is not there yet.
Quick Hits
Settra ransomware is breaking into retail and manufacturing firms through stolen VPN credentials, no phishing required, according to Huntress.
Metaencryptor ransomware hit a South Korean camera module maker and a Japanese auto parts supplier this week, both through unpatched edge devices.
NightmareStresser, a DDoS-for-hire service running since 2022, is shut down, its operator ordered to pay 1.2 million dollars to victims.
BragJack abuses a Chrome extension API to hijack AI agent browsing sessions, redirecting them without the user noticing, a preview of what AI-agent security holes look like.
Tool of the Week
YubiKey 5 NFC is a hardware security key that gives you phishing-resistant two-factor authentication on accounts that support it. For anyone whose employer runs Microsoft 365 (see story three), this is the cheapest fix for account takeover that actually works.
Protect Yourself
If you or your work uses Microsoft 365, check your sign-in activity this week. Go to myaccount.microsoft.com, then Sign-in activity, and look for locations or devices you do not recognise. Revoke anything odd. Given over 5,700 accounts have been hit by one automated tool this month, this two minute check is worth doing today, wherever you are.
Forwarded this? Get your own cybersecurity briefing at futuretechnologyhq.com/newsletter
Stay safe out there. Nath, Future Technology
Some links in this newsletter may be affiliate links. We only recommend products we genuinely think are worth your time.