AI Malware Votes on Its Next Attack — Plus the FBI Hack Claim and a Data Broker's Downfall
Wednesday, September 23, 2026 · 5-minute read
A Chinese-speaking threat group hit nearly 1,000 network switches and pulled more than 18,500 records from government backend databases. They got in by exploiting known security holes in ZyXEL managed network switches and WordPress websites — two very common pieces of technology used by organizations worldwide. If you run a WordPress site or use ZyXEL networking gear, this is a reminder that unpatched software is an open door.
↗ BleepingComputerThe ShinyHunters extortion gang says it broke into FBI systems using a previously unknown flaw in Oracle PeopleSoft, software the government uses for HR and job applications. They claim to have stolen data on FBI employees and job applicants. The FBI has not confirmed the breach, and ShinyHunters has a history of making bold claims to grab attention and pressure victims into paying.
↗ BleepingComputerSweden's privacy watchdog fined IT provider Miljödata after a breach in August 2025 exposed the personal data of 2.2 million people. Regulators found the company had not put adequate security measures in place — a familiar story that keeps costing companies real money under Europe's strict data protection rules. The fine works out to roughly eight cents per person affected, which gives you a sense of the scale involved.
↗ BleepingComputerCheck Point — a company that sells firewall and security products used by thousands of businesses — rushed out emergency fixes for a zero-day vulnerability in its Security Management Server. The flaw lets attackers run their own scripts on the server remotely, which could give them control over an organization's entire network security setup. Check Point confirmed the vulnerability is being actively exploited right now, meaning someone is already using it against real targets.
PhaaS (Phishing-as-a-Service) platform EvilTokens was disrupted after it had already successfully hijacked 12,000 Microsoft accounts. EvilTokens worked by sitting in the middle of a real login — when victims typed their credentials, the service captured them in real time, bypassing multi-factor authentication in the process. This is the modern version of phishing: it doesn't just steal your password, it steals the session cookie that keeps you logged in.
A flaw in cPanel's calendar and contacts service lets anyone with a basic hosting account run commands as the root user and take full control of the server. On a shared hosting server, that means any paying customer — or anyone who steals a customer's login — could own the whole machine and every other website on it. A second related flaw lets one hosting account tamper with another account's databases.
Status: Patches released by cPanel on September 22. Update immediately through your hosting provider or cPanel dashboard.
F5's BIG-IP APM product — used by large companies and government agencies to manage who gets access to their networks — has a critical remote code execution zero-day being actively exploited in the wild. An attacker who hits this flaw can run arbitrary commands on the device without needing a valid login. BIG-IP gear sits right at the edge of corporate networks, making this a high-value target.
Status: Security updates released by F5 on September 23. Patch now — this is being actively exploited.
Arista Networks patched a zero-day in VeloCloud Orchestrator, software that businesses use to manage their SD-WAN networks. Attackers are already exploiting the flaw in real deployments. If an attacker gains control of the orchestrator, they can manipulate network traffic across the entire organization.
Status: Patches released September 23. Apply immediately to on-premises deployments.
A newly discovered zero-day in Windows Defender can stop Microsoft's antivirus from receiving its regular updates. That means a computer running a vulnerable version could go unprotected against new malware, without the user ever knowing their defenses have been quietly switched off. Microsoft has acknowledged the issue.
Status: Fix in progress. Keep Windows Update enabled and watch for an out-of-band patch.
Cisco Talos released CAIRN, a free open-source tool built specifically to find malware that talks to AI model APIs. The need for it became obvious when Talos discovered CLOSEDQUORUM — a new piece of Windows malware that routes its attack decisions through up to four different AI models instead of a traditional hacker-controlled server. CAIRN works by scanning code and network behavior for the telltale patterns of AI service communication, something no existing tool was designed to catch. It's a rare case of defenders getting a new tool specifically built for an emerging threat rather than retrofitting old ones. The tool is publicly available, meaning independent researchers and small security teams can use it at no cost.
↗ The Hacker NewsSecurity researchers built a working proof-of-concept attack where a hacker with privileged access inside a company's system registers a fake external MFA provider. From that position, the rogue provider intercepts real login attempts and silently captures passwords — even though the user sees a completely normal login screen and successfully gets in. The attack works because many identity systems trust external MFA providers implicitly, once they're registered. The researchers published their findings to push vendors to add registration controls.
↗ BleepingComputerRadaris.com built one of the internet's largest collections of personal data — home addresses, phone numbers, relatives, background checks — on millions of Americans. For years, people who asked to have their information removed were largely ignored. That finally caught up with the company in a New Jersey courtroom, where a judge ordered the radaris.com domain transferred to the plaintiffs after the company's owners refused to properly appear and defend themselves.
The lawsuit was brought under New Jersey's Daniels Law, which gives law enforcement officers, judges, and government workers the right to have their personal information scrubbed from data broker sites. When Atlas Data Privacy Corp sued Radaris in 2024, the company's owners — Russian-born brothers Igor and Dmitry Lubarsky — ran a years-long playbook to avoid accountability. They invented a fake CEO named "Gary Norden," shifted company ownership through a revolving door of shell companies in the Marshall Islands, British Virgin Islands, and Seychelles, and changed privacy policies constantly to muddy the legal trail. At one point, they created a brand new company in the Marshall Islands to claim as the real owner — but Atlas hired a local investigator who found the entity didn't even exist yet.
This matters for regular people because data brokers like Radaris aggregate personal information that can be used for stalking, harassment, identity theft, and targeted scams. Most people have no idea their home address, daily routine clues, and family connections are sitting on dozens of these sites, freely searchable by anyone willing to pay a few dollars. Law enforcement officers face an especially acute risk — knowing a police officer's home address is a genuine physical threat.
The domain transfer is a meaningful win, but the underlying data doesn't disappear overnight, and the Lubarsky brothers haven't faced personal criminal consequences. Watch for whether other Radaris-affiliated sites — the company operated more than a dozen — get pulled into the same legal net. It also signals that the "delay and confuse" strategy data brokers have relied on for a decade may finally be running out of runway in U.S. courts.