- Cl0pFellow cybercriminal outfit whose darknet website was hijacked
- LAPSUS$Associated with Scattered LAPSUS$ Hunters group
- HellcatRansomware group Rey was an administrator for
apply.fbijobs[.]govFBI portal allegedly hacked by ShinyHunters
The cybersecurity landscape continues to evolve with significant developments in threat actor arrests, espionage campaigns targeting critical sectors, and exploitation of widely-used enterprise platforms. Today's security briefing covers major incidents spanning from law enforcement cooperation with digital extortion groups to coordinated nation-state operations targeting artificial intelligence policy experts and critical infrastructure across multiple continents.
A suspected member of the ShinyHunters digital extortion group, operating under the online alias "Rey," has reportedly been detained by authorities in Jordan. According to Reuters sources, the suspect, identified as Saif al-Din Khader, was brought into custody on September 29, 2026, and is cooperating with the U.S. Federal Bureau of Investigation to identify other group members. Source: ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
This development represents a significant breakthrough in disrupting organized digital extortion operations. The cooperation between international law enforcement and the detained suspect may provide critical intelligence on the group's infrastructure, operational methods, and additional members involved in extortion campaigns.
A China-nexus cyber espionage group designated as TA419 has been conducting credential phishing campaigns against artificial intelligence experts employed by U.S. think tanks, universities, and legal sector organizations. The threat actor impersonated prominent economists, AI policymakers, and employees from organizations like Anthropic to target AI policy specialists. Source: China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
This campaign demonstrates a strategic focus on intelligence gathering related to U.S. artificial intelligence policy development and expertise. The targeting of policy experts suggests an intent to gain insights into emerging AI regulatory frameworks and technological advancement strategies.
The China-linked ransomware group Warlock has targeted critical infrastructure organizations including a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities for initial access. The attacks leveraged multiple SharePoint-related CVEs including CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771, and CVE-2025-1055. Source: Warlock ransomware breach SharePoint in water, telecom operator attacks
These attacks underscore the critical risk posed by unpatched SharePoint instances in organizations managing essential services. The targeting of water utilities and telecommunications infrastructure represents a direct threat to public safety and national security resilience.
Government and policy organizations across Asia have been targeted by a China-nexus threat actor deploying a previously undocumented backdoor called Antino. The campaign has affected government and policy entities in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, with the backdoor leveraging Outlook and OneDrive for command and control communications. Source: Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
The use of legitimate Microsoft 365 services for command and control represents a sophisticated evasion technique that complicates detection and attribution. This campaign highlights the vulnerability of government institutions across the Asia-Pacific region to advanced persistent espionage operations.
Today's threat landscape reflects intensifying nation-state operations targeting both critical infrastructure and policy-making institutions, alongside successful law enforcement actions disrupting organized cybercrime groups. Organizations must prioritize patch management, employee security awareness, and monitoring of legitimate service abuse for command and control purposes.
Source articles and extracted indicators (defanged where appropriate).
apply.fbijobs[.]govrsproxy[.]cnd32tpl7xt7175h.cloudfront[.]net