Top stories.
- ShinyHunters claims to have breached the FBI.
- Australia says an OpenAI agent hacked a government website.
- Kiteworks urges customers to shut down vulnerable servers.
- Microsoft disrupts the EvilTokens cybercrime platform.
- Nightmare Eclipse publishes another Defender zero-day.
ShinyHunters claims to have breached the FBI.
The ShinyHunters extortion gang claims to have breached the US FBI and stolen information on nearly all of the Bureau’s employees, Reuters reports. The crooks shared a sample of data containing FBI employees’ names, home addresses, Social Security numbers, assignments, and the names of their family members.
Reuters confirmed that at least some of the information is accurate, saying the sample contains “granular detail about scores of bureau officials’ job assignments, including sensitive work against Chinese spies, Russian intelligence, drug cartels, and more.” 404 Media notes that the breach also appears to have exposed members of the FBI’s secretive hacking team, the Remote Operations Unit.
The FBI is investigating the alleged hack, and sources familiar with the matter told Politico that investigators believe the extortion group’s claims are credible. One source told the publication that the hackers appear to have exploited a vulnerability in Oracle PeopleSoft to breach the FBI’s online jobs portal.
ShinyHunters says the hack isn’t financially motivated but serves as payback for the FBI’s advising victims not to pay ransoms to extortion groups.
Australia says an OpenAI agent hacked a government website.
Australia’s Prime Minister Anthony Albanese stated that an OpenAI agent breached a government health data portal and gained unauthorised access to files, Reuters reports. The incident would be the first known instance of a rogue AI agent hacking a government system outside the United States. The Prime Minister expressed “extreme concern about this incident” to OpenAI CEO Sam Altman, noting that he was deeply disappointed by the company’s delay in notifying the government. The incident took place in June 2026, and OpenAI did not notify Australian officials until September 10th.
OpenAI said in a statement, “Our review found no evidence of patient records being accessed. The information accessed included aggregate health statistics and internal file names," adding that it "identified activity involving several Australian government websites and services as our models attempted to look up answers ... our models took actions we did not intend.”
The Record notes that security experts have questioned the claims of a hack. Archived versions of the affected website explicitly directed users to an unauthenticated endpoint, so the AI agent may have simply been following instructions from the misconfigured website itself. Ciaran Martin, former chief of the UK's National Cyber Security Centre, stated, "It’s still unclear if what's happened would constitute a hack in the normal sense of the term."
Kiteworks urges customers to shut down vulnerable servers.
Secure file-sharing platform Kiteworks has advised customers to temporarily shut down their servers in anticipation of a zero-day attack campaign, Heise Security reports. Kiteworks CISO Frank Balonis said in an email to customers obtained by Heise, “We have received credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend. We strongly recommend you shut down your Kiteworks system for six hours.”
The company hasn’t released details of the potential zero-day flaw, but the unusual recommendation to shut down all servers until a fix is available indicates that Kiteworks believes the situation is serious.
Microsoft disrupts the EvilTokens cybercrime platform.
Microsoft this week announced the seizure of fifty websites used by the AI-assisted phishing service EvilTokens. The service helped criminals obtain email access through device-code phishing, then used AI to analyze compromised inboxes, map relationships and financial processes, identify promising targets, and recommend fraud strategies. Microsoft says EvilTokens was tied to the compromise of more than 12,000 email inboxes across over 10,000 organizations worldwide since the kit surfaced in February 2026.
Microsoft and the Health-ISAC disrupted the platform with assistance from Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. The operation was authorized by the US District Court for the Eastern District of Virginia. Police in the UK also arrested two men in connection with the operation. The two suspects have been released on bail while the investigation continues.
Nightmare Eclipse publishes another Defender zero-day.
Security researcher Nightmare Eclipse, who recently disclosed his real identity as former Microsoft employee Abdelhamid Naceri, has dropped another Microsoft Defender zero-day exploit, BleepingComputer reports. The exploit is similar to a zero-day Naceri released in April, and can be used to block antivirus updates.
Naceri has published eleven Windows zero-days over the past year in a protest campaign against Microsoft. He revealed his identity in an X thread this month, saying he was unfairly terminated from the Microsoft Security Response Center (MSRC) in September 2024.