Our analyst team shares a few articles each week in our email newsletter which goes every Thursday. Make sure to register! This blog highlights those articles in order of what was the most popular in our newsletter – what our readers found the most intriguing. Stay tuned for a recap every month. We hope sharing these resources and news articles emphasizes the importance of cybersecurity and sheds light on the latest in threat intelligence.

ShinyHunters has announced on their data leak site to have breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. The post claims “We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job”. ShinyHunters claimed it targeted the FBI in response to a May 2026 public service announcement warning about the group’s targeting of Canvas, an online learning management system, and urging victims not to pay. The group disputed the FBI’s claims, calling them “substantial false allegations” and denying links to the Com cybercriminal collective, which it described as industry-driven “propaganda.” Read full article.

Google Threat Intelligence Group (GTIG) reports that threat actors are increasingly targeting enterprise AI assets for espionage, extortion, and resource theft. Observed activity includes the theft of API credentials and proprietary AI data, including models, prompts, source code, and research, as well as the compromise of cloud environments to run unauthorized AI workloads. Financially motivated threat group, TeamPCP, has targeted software supply chains and AI coding assistants, while China-nexus actors have reportedly deployed local LLM infrastructure and conducted attacks against AI models to evade provider monitoring and extract proprietary capabilities. GTIG has also observed adversaries using agentic AI to accelerate malware and tooling development, underscoring the growing role of AI as both a target and an operational force multiplier for cyber threat actors. Read More.
Nimbus Manticore, the Iranian hacking group, has been connected to two (NodeRabbit and PollCat) previously undocumented malwares targeting Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Nimbus Manticore, also known as Iranian Dream Job, has been targeting job candidates with fake recruitment coding challenges designed to infect their computers. In one case, attackers distributed a project-management application called Taskflow and asked candidates to find bugs in the frontend within three hours. The challenge appeared legitimate, but malicious code was hidden in the supposedly “bug-free” server.js file. It loaded a trojanized Node.js package that secretly launched NodeRabbit, a backdoor capable of communicating with attacker-controlled servers. Once installed, NodeRabbit can collect system information, run commands, access and modify files, manage directories, and gather network details. It can also execute temporary scripts and delete them afterward to hide evidence of its activity. Read more here.
According to a joint cyber security advisory, North Korean threat actors (WarPlum) behind the Contagious Interview campaign have compromised at least “30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets”. A joint alert from cybersecurity and intelligence agencies in Japan, the U.S., Australia, and Germany warn of a campaign targeting web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3. The threat actors have stolen an estimated $10.71 million or more in cryptocurrency. According to the alert, the group “conducts cyber-attacks by infiltrating unsuspecting job seekers’ computer networks, harvesting sensitive information, and stealing cryptocurrency.”. Following initial access, a variety of malware is deployed in an attempt to ensure access is gained. Read here.
Researchers have uncovered a new tactic used by the threat actor known as Fire Ant, after identifying an active Generic Routing Encapsulation (GRE) tunnel interface on a Cisco IOS XR router that could not be accounted for by the device’s running configuration or commit history.
According to incident response firm Sygnia, Fire Ant activity “strongly overlaps” with the Chinese espionage group, UNC3886. Fire Ant has expanded its targeting beyond VMware hypervisors to include Cisco routers, TACACS authentication servers, and Linux management hosts. Further analysis of the compromised router revealed custom malware designed to maintain persistent access through a fake system service that activated the implant only during alternating hours, helping it evade detection.. Learn more.
On September 15, the FBI seized the domains of NightmareStresser, one of the longest-running DDoS-for-hire platforms. The service allowed users to rent access to compromised routers and IoT devices to launch large-scale distributed denial-of-service (DDoS) attacks. Before its domains were taken down, NightmareStresser claimed more than 566,000 registered users and the ability to generate attacks of up to 200 Gbps. According to the FBI, the platform was used to launch hundreds of thousands of actual or attempted DDoS attacks against targets worldwide since 2022. Read full article.

The Spanish Data Protection Agency (AEPD) was notified of an alleged cyberattack involving an AI agent powered by a known large language model (LLM). The victim organization reported that the attack autonomously identified vulnerabilities, gained access to systems, modified personal data, and accessed financial documents. While the AEPD has not yet investigated or verified the incident, it said the report highlights how AI could increase the speed, scale, and adaptability of cyberattacks, reducing the time defenders have to respond. The agency recommends that organizations strengthen identity and credential security, improve rapid detection and containment capabilities, and update security and data protection strategies to account for AI-assisted and autonomous attacks. Read full article.

On September 08, ShinyHunters claimed on its data leak site to have breached DAVID, an online database platform used by the Florida Department of Motor Vehicles and exfiltrated more than 200,000 driver records. According to the threat actors, they gained access to DAVID by exploiting a password-reset vulnerability that enabled them to compromise multiple accounts. ShinyHunters further claimed that, after obtaining access, they enumerated records by ID and downloaded associated HTML pages and driver images. The group alleges that this activity resulted in the theft of more than 200,000 records, with the operation beginning on September 3. Learn more.
Products
Services
Use Cases