Torn-paper collage of an ID badge, redacted personnel files, a phone showing a passkey prompt, and a network gateway, with a red crosshair sliding from one to the next

ShinyHunters Hits the FBI, Pentagon Records Leak, and "Update Your Passkey" Becomes a Lure

Last week: ShinyHunters claims the FBI, Pentagon personnel records sat exposed for nine months, help desk impersonators use passkey enrollment as bait, and two NetScaler zero-days.

Torn-paper collage of an ID badge, redacted personnel files, a phone showing a passkey prompt, and a network gateway, with a red crosshair sliding from one to the next

Last week's common thread: the safeguard you were counting on. A web firewall rule standing in for a patch. A phone call standing in for identity verification. A third-party security tool holding admin credentials. Each one became the way in. Here's what mattered.

The lead: ShinyHunters says it breached the FBI

The extortion crew ShinyHunters claims it took about 2 TB of data from FBI systems, including the FBIjobs.gov portal, HR services, and a Medlink database it says holds medical records, according to The Hacker News. The group says it used a new, unpatched Oracle PeopleSoft zero-day and called the attack retaliation for an FBI warning about its earlier campaigns. The FBI said only that it is "aware of claims regarding unauthorized activity affecting FBIjobs.gov" and is investigating.

Days later, Google's Mandiant reported that the same group has resumed attacks on CVE-2026-35273, a critical PeopleSoft flaw Oracle patched on June 10. The trick is almost insultingly simple: URL-encoding a single character in the request path (/%50SEMHUB/ instead of /PSEMHUB/) slips past web application firewall rules that match the literal string, while the PeopleSoft server decodes and processes the request normally. Targets span higher education, healthcare, technology, transportation, and government.

Takeaway: A WAF rule buys time. It is not a patch. If you run PeopleSoft, confirm the June fix is actually installed, hunt for signs of earlier compromise, and keep PeopleSoft off the open internet until the claimed new zero-day is understood.

Pentagon personnel records sat exposed for nine months

The Defense Manpower Data Center, which maintains the Defense Department's personnel records, is notifying about 2.8 million living service members and staff, plus roughly 300,000 deceased individuals, that their data was exposed, TechCrunch reports. A vulnerability in a file-sharing system gave unauthorized users access to a server holding unencrypted Social Security numbers, names, dates of birth, race, and military service details. Access ran from October 2025 until the flaw was discovered on July 16, 2026. Letters went out on Sept. 18, with one year of credit monitoring offered, according to Military Times, which cited sources putting the total closer to 4 million. Who was behind it is unknown.

Takeaway: The vulnerability opened the door. The lack of encryption and nine months without detection made it a catastrophe. Encrypt sensitive records at rest, and alert on bulk reads from file-sharing servers. Unlike a password, a Social Security number can never be rotated.

"Update your passkey" is the new phishing lure

Microsoft detailed a campaign in which attackers call or text employees while posing as the IT help desk, urging them to "update" their passkey or MFA. Victims are steered to adversary-in-the-middle phishing pages or device-code sign-in flows that hand over their session. The passkeys themselves were never broken. The attackers simply used them as the pretext.

Once inside, they registered their own MFA methods to keep access, mapped users, roles, and apps through Microsoft Graph, and pulled mail, SharePoint, and OneDrive files for hours or days at a time.

Takeaway: Enforce phishing-resistant MFA through Conditional Access, require managed devices for sensitive apps, block device-code flow where you don't need it, and alert on every new MFA method registration. Then tell your people plainly: IT will never call and ask you to enroll a credential through a link.

NetScaler, again

Citrix fixed two critical NetScaler ADC and Gateway zero-days on Sept. 27: CVE-2026-88771, which allows unauthenticated command execution, and CVE-2026-88772, a memory overflow that enables code execution when DTLS is on. Both score 9.5. GreyNoise saw exploitation attempts as early as Sept. 24, and Palo Alto Networks' Unit 42 counted more than 50,000 exposed instances, per The Hacker News. CISA gave federal agencies until Sept. 30 to act.

Takeaway: If an internet-facing NetScaler was unpatched after Sept. 24, treat it as compromised, not just vulnerable. Preserve evidence, rebuild on current firmware, and rotate every credential and session key that passed through it.

Quick hits

  • Bitget lost about $387.5 million from hot and warm wallets on Sept. 24. The exchange says a flaw in a third-party security product handed the attacker high-level internal credentials, which were used to push withdrawals past its risk controls. Customer balances and cold wallets were untouched.
  • Apple patched CVE-2026-86950, a CoreGraphics zero-day it says may have been used in "an extremely sophisticated attack" on specific individuals. Update to iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1, or macOS Sequoia 15.8.1.
  • KillSec is down. Police in Spain, the UK, and Romania made arrests on Sept. 30, including a 16-year-old suspected of running the operation, and seized its leak site, five servers, and 110 TB of data. Investigators tie the group to about 500 successful attacks.
  • Microsoft Entra ID will begin enforcing a Content Security Policy on its sign-in pages in mid-to-late October, blocking scripts that browser extensions or third-party tools inject. Test your sign-in flows now so nothing breaks on rollout day.
  • Cybersecurity Awareness Month started Oct. 1. Our four-week action plan turns it into something more useful than a poster campaign.

Bottom line

Every story last week ended at an identity: an applicant database, a personnel file, an MFA enrollment, an admin credential. Patch the edge, but verify the person. Know who is registering new sign-in methods, who holds standing admin access, and what an intruder could read if they had been inside since last October.

Share

Related articles

AI-Powered Hacking Has Entered Its Operational Phase
Newsletter

AI-Powered Hacking Has Entered Its Operational Phase

AI is making cyberattacks faster, more scalable, and easier to execute. This article reviews the current threat level and explains how stronger identity controls, phishing-resistant authentication, and proximity-based security help organizations respond.

Your MFA Just Got Phished
Newsletter

Your MFA Just Got Phished

Phishing kits are now defeating multi-factor authentication at scale — hijacking fully MFA-verified Microsoft 365 logins without ever touching a password. Why the second factor you trust isn't the finish line, and what actually resists phishing.