“ShinyHunters” — 53 distilled results

The hacker group ShinyHunters claimed a breach of cybersecurity firm ReliaQuest after using social engineering to compromise an employee's Okta dashboard session. ReliaQuest confirmed the incident was

The hacker group ShinyHunters claimed a breach of cybersecurity firm ReliaQuest after using social engineering to compromise an employee's Okta dashboard session. ReliaQuest confirmed the incident was contained, stating that no internal systems or customer data were accessed during the brief security event.

Weekly Cybersecurity Incidents and Threat Reports

Multiple unrelated cybersecurity threats were reported this week including malware campaigns impersonating Windows apps, hidden iOS tracking data streams, Iranian state-sponsored industrial system interference, and an API vulnerability in the Vatican's mobile app. Additional coverage addressed AI security concerns and emerging shadow AI agent threats.

Cybercrime group ShinyHunters claims FBI recruitment database breach

Between 22 and 25 September, cybercriminal group ShinyHunters claimed it exploited a zero-day vulnerability in Oracle PeopleSoft software to breach FBI recruitment systems (FBIJobs.gov), stealing 2–3 terabytes of sensitive employee data and information on job applicants and relatives. The FBI confirmed investigation on 23 September.

Multiple critical cybersecurity vulnerabilities disclosed

Security researchers and vendors disclosed numerous critical vulnerabilities including zero-day flaws in SonicWall SMA1000 devices, infrastructure flaws tracked in an InfraTrust report, and large-scale malware campaigns using GitHub repositories and DDoS botnets. The Dysphoria botnet has infected approximately 200,000 devices worldwide.

Dutch news digest social posts

Six unrelated social media posts link to Dutch news teletekst pages covering an arrest (ShinyHunters suspect), deaths off Puerto Rico, Spanish property ruling, RAF base suspects released, station evacuations, and highway closure. The posts contain only headlines and links, no substantive reporting.