Breaking News – Cyber Threats – 2026-09-28 13:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-28 13:00 PDT
- Dutch police confirm arrest in ShinyHunters hacking investigation
BleepingComputer • 2026-09-28 12:49 • www.bleepingcomputer.com
Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group. […]
https://www.bleepingcomputer.com/news/security/dutch-police-confirm-arrest-in-shinyhunters-hacking-investigation/ - Misconfigured Supabase apps expose data in over 16,000 databases
BleepingComputer • 2026-09-28 11:50 • www.bleepingcomputer.com
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. […]
https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/ - IAM for AI agents: A Practical Enterprise Framework
The Hacker News • 2026-09-28 11:20 • thehackernews.com
What is IAM for AI agents?AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of conventional provisioning, the components that matter, how to evaluate framework choices, and what runtime evidence proves an agent behaved as intended.
https://thehackernews.com/2026/09/iam-for-ai-agent.html - Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
The Hacker News • 2026-09-28 10:42 • thehackernews.com
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday.The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget’s wallet system.
Exchanges keep most
https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html - RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
The Hacker News • 2026-09-28 10:38 • thehackernews.com
RatHat’s operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy.The console stores what the malware collects from each phone,
https://thehackernews.com/2026/09/rathat-android-malware-console-uses.html - JadePuffer agentic AI attacks target Azure, destroy cloud resources
BleepingComputer • 2026-09-28 08:49 • www.bleepingcomputer.com
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. […]
https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/ - Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
KrebsOnSecurity • 2026-09-28 08:08 • krebsonsecurity.com
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.
https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/ - ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
The Hacker News • 2026-09-28 07:00 • thehackernews.com
A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface.Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing
https://thehackernews.com/2026/09/weekly-recap-387m-crypto-hack-citrix.html - 80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
BleepingComputer • 2026-09-28 07:00 • www.bleepingcomputer.com
Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI logins and how organizations can identify their exposure. […]
https://www.bleepingcomputer.com/news/security/80-000-plus-organizations-had-ai-logins-stolen-from-shadow-ai-to-llmjacking/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.