← All issues
cybersecurityCyberBubbleAI malware

AI Malware Votes on Its Next Attack — Plus the FBI Hack Claim and a Data Broker's Downfall

🌐  World Intel
China: Hackers Exploit WordPress and Router Bugs to Steal Government Data

A Chinese-speaking threat group hit nearly 1,000 network switches and pulled more than 18,500 records from government backend databases. They got in by exploiting known security holes in ZyXEL managed network switches and WordPress websites — two very common pieces of technology used by organizations worldwide. If you run a WordPress site or use ZyXEL networking gear, this is a reminder that unpatched software is an open door.

↗ BleepingComputer
USA: ShinyHunters Gang Claims It Hacked the FBI Using an Oracle Flaw

The ShinyHunters extortion gang says it broke into FBI systems using a previously unknown flaw in Oracle PeopleSoft, software the government uses for HR and job applications. They claim to have stolen data on FBI employees and job applicants. The FBI has not confirmed the breach, and ShinyHunters has a history of making bold claims to grab attention and pressure victims into paying.

↗ BleepingComputer
Sweden: Data Broker Fined $183,000 After 2.2 Million People's Records Exposed

Sweden's privacy watchdog fined IT provider Miljödata after a breach in August 2025 exposed the personal data of 2.2 million people. Regulators found the company had not put adequate security measures in place — a familiar story that keeps costing companies real money under Europe's strict data protection rules. The fine works out to roughly eight cents per person affected, which gives you a sense of the scale involved.

↗ BleepingComputer
⚔️  Active Attacks
Check Point Security Management Servers Under Active Attack

Check Point — a company that sells firewall and security products used by thousands of businesses — rushed out emergency fixes for a zero-day vulnerability in its Security Management Server. The flaw lets attackers run their own scripts on the server remotely, which could give them control over an organization's entire network security setup. Check Point confirmed the vulnerability is being actively exploited right now, meaning someone is already using it against real targets.

🛡 What to do: If your organization uses Check Point Security Management Server, apply the emergency hotfix immediately — don't wait for your next scheduled patch window.
EvilTokens Phishing Service Taken Down After Hijacking 12,000 Microsoft Accounts

PhaaS (Phishing-as-a-Service) platform EvilTokens was disrupted after it had already successfully hijacked 12,000 Microsoft accounts. EvilTokens worked by sitting in the middle of a real login — when victims typed their credentials, the service captured them in real time, bypassing multi-factor authentication in the process. This is the modern version of phishing: it doesn't just steal your password, it steals the session cookie that keeps you logged in.

🛡 What to do: Switch from SMS-based two-factor codes to a hardware security key or a passkey where possible — these are much harder for middle-in-the-middle phishing kits to defeat.
🔓  New Vulnerabilities
cPanel CalDAV/CardDAV cPanel Hosting Control Panel CRITICAL

A flaw in cPanel's calendar and contacts service lets anyone with a basic hosting account run commands as the root user and take full control of the server. On a shared hosting server, that means any paying customer — or anyone who steals a customer's login — could own the whole machine and every other website on it. A second related flaw lets one hosting account tamper with another account's databases.

Status: Patches released by cPanel on September 22. Update immediately through your hosting provider or cPanel dashboard.

F5 BIG-IP APM F5 BIG-IP Access Policy Manager CRITICAL

F5's BIG-IP APM product — used by large companies and government agencies to manage who gets access to their networks — has a critical remote code execution zero-day being actively exploited in the wild. An attacker who hits this flaw can run arbitrary commands on the device without needing a valid login. BIG-IP gear sits right at the edge of corporate networks, making this a high-value target.

Status: Security updates released by F5 on September 23. Patch now — this is being actively exploited.

Arista VeloCloud Orchestrator Arista Networks VCO On-Prem HIGH — ACTIVELY EXPLOITED

Arista Networks patched a zero-day in VeloCloud Orchestrator, software that businesses use to manage their SD-WAN networks. Attackers are already exploiting the flaw in real deployments. If an attacker gains control of the orchestrator, they can manipulate network traffic across the entire organization.

Status: Patches released September 23. Apply immediately to on-premises deployments.

Windows Defender Microsoft Windows Defender Antivirus HIGH

A newly discovered zero-day in Windows Defender can stop Microsoft's antivirus from receiving its regular updates. That means a computer running a vulnerable version could go unprotected against new malware, without the user ever knowing their defenses have been quietly switched off. Microsoft has acknowledged the issue.

Status: Fix in progress. Keep Windows Update enabled and watch for an out-of-band patch.

🛠  New Tech
CAIRN: Cisco's Open-Source Tool for Hunting AI-Powered Malware

Cisco Talos released CAIRN, a free open-source tool built specifically to find malware that talks to AI model APIs. The need for it became obvious when Talos discovered CLOSEDQUORUM — a new piece of Windows malware that routes its attack decisions through up to four different AI models instead of a traditional hacker-controlled server. CAIRN works by scanning code and network behavior for the telltale patterns of AI service communication, something no existing tool was designed to catch. It's a rare case of defenders getting a new tool specifically built for an emerging threat rather than retrofitting old ones. The tool is publicly available, meaning independent researchers and small security teams can use it at no cost.

↗ The Hacker News
Rogue MFA Provider Attack: Researchers Show How a Trusted Login Can Steal Your Password

Security researchers built a working proof-of-concept attack where a hacker with privileged access inside a company's system registers a fake external MFA provider. From that position, the rogue provider intercepts real login attempts and silently captures passwords — even though the user sees a completely normal login screen and successfully gets in. The attack works because many identity systems trust external MFA providers implicitly, once they're registered. The researchers published their findings to push vendors to add registration controls.

↗ BleepingComputer
💡  Deep Dive
A People-Search Website Spent Years Hiding Behind Shell Companies. A Court Just Took Its Domain Away.

Radaris.com built one of the internet's largest collections of personal data — home addresses, phone numbers, relatives, background checks — on millions of Americans. For years, people who asked to have their information removed were largely ignored. That finally caught up with the company in a New Jersey courtroom, where a judge ordered the radaris.com domain transferred to the plaintiffs after the company's owners refused to properly appear and defend themselves.

The lawsuit was brought under New Jersey's Daniels Law, which gives law enforcement officers, judges, and government workers the right to have their personal information scrubbed from data broker sites. When Atlas Data Privacy Corp sued Radaris in 2024, the company's owners — Russian-born brothers Igor and Dmitry Lubarsky — ran a years-long playbook to avoid accountability. They invented a fake CEO named "Gary Norden," shifted company ownership through a revolving door of shell companies in the Marshall Islands, British Virgin Islands, and Seychelles, and changed privacy policies constantly to muddy the legal trail. At one point, they created a brand new company in the Marshall Islands to claim as the real owner — but Atlas hired a local investigator who found the entity didn't even exist yet.

This matters for regular people because data brokers like Radaris aggregate personal information that can be used for stalking, harassment, identity theft, and targeted scams. Most people have no idea their home address, daily routine clues, and family connections are sitting on dozens of these sites, freely searchable by anyone willing to pay a few dollars. Law enforcement officers face an especially acute risk — knowing a police officer's home address is a genuine physical threat.

The domain transfer is a meaningful win, but the underlying data doesn't disappear overnight, and the Lubarsky brothers haven't faced personal criminal consequences. Watch for whether other Radaris-affiliated sites — the company operated more than a dozen — get pulled into the same legal net. It also signals that the "delay and confuse" strategy data brokers have relied on for a decade may finally be running out of runway in U.S. courts.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →