Cyber Security News

Start. Stay. Grow.

Curated daily. The latest hacks, breaches, and cyber trends—humanized.

Daily cyber brief

Hacking Editorial Brief — September 22, 2026

ShinyHunters Breaches Clop Ransomware Gang's Infrastructure

Threat actor ShinyHunters has successfully compromised the infrastructure of rival ransomware operation Clop, breaching the gang's leak site and threatening to expose victim payment data. The breach represents an unusual case of one cybercriminal group targeting another's operational infrastructure, creating secondary risks for organizations that may have previously paid ransoms to Clop. The incident raises concerns about the security of sensitive negotiation and payment records held by ransomware operations, which could be weaponized for further extortion or exposed publicly. ShinyHunters' ability to penetrate Clop's systems underscores vulnerabilities even within established criminal infrastructure.

Russian Actor Leverages AI to Exploit PaperCut Vulnerabilities at Scale

A suspected Russian-speaking threat actor has been observed using artificial intelligence to develop exploits targeting recently disclosed vulnerabilities in PaperCut NG/MF print management software, successfully compromising hundreds of instances. The campaign demonstrates operationalization of AI tools for exploit development and deployment at scale, representing a tactical evolution in how threat actors accelerate weaponization of disclosed vulnerabilities. The targeting of PaperCut, widely deployed in enterprise and education environments, suggests the actor is focused on broad access rather than specific vertical targeting. The incident follows broader industry concerns about AI-assisted offensive capabilities, now confirmed in active operations.

Supply Chain Attack Compromises Popular Python Face-Swapping Application

Attackers successfully injected a malicious dependency into Deep-Live-Cam, a Python-based face-swapping tool with 96,600 GitHub stars, in a supply chain attack targeting the project's dependency chain. The compromise demonstrates continued threat actor focus on open-source projects with large user bases as vectors for downstream attacks. The method of injecting malicious source dependencies rather than compromising the primary codebase reflects sophisticated understanding of software supply chain trust relationships and build processes.


Sources: Dark Reading · The Hacker News · Malware Patrol

Around the Web

Last Updated: N/A

Hacker icon

Hacks + Heists

Russian Threat Actor Using AI to Rapidly Develop Exploits for PaperCut Vulnerabilities

A suspected Russian-speaking cyber actor is using artificial intelligence to devise exploits targeting PaperCut NG/MF security flaws and break into hu...

Read more →

Cybercriminal group claims to steal thousands of FBI employee records - POLITICO

The FBI said it was probing a suspected hack, after the cybercriminal group ShinyHunters claimed to have breached its systems.

Read more →

FBI investigating apparent breach after hackers claim to have stolen thousands of federal ... - CNN

The FBI is investigating an apparent breach of its networks after a prolific cybercriminal group claimed on Tuesday to have stolen thousands of ...

Read more →

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

Microsoft released fixes for a maximum-severity CVSS 10.0 security flaw in Azure AI Foundry (CVE-2026-85889) that could allow unauthenticated attacker...

Read more →

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

The Hacker News has contacted Hacktron with questions about how the forum code execution was achieved and about the scope of the account access. What ...

Read more →
Cybersecurity icon

Big Cyber

ShinyHunters Claims FBI System Compromise, Issues Extortion Threat

ShinyHunters claimed to have compromised FBI systems including CJ, HR, and Medlink, issuing threats to expose sensitive data about FBI agents and appl...

Read more →

Google's Gemini goes rogue, hacks real company systems during key cybersecurity test

Google's Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities, the first known example of the...

Read more →

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

"At this time, there is no indication that this vulnerability has been exploited in the wild," the notice said. The U.S. Cybersecurity and ...

Read more →

What Companies Actually Need as Cybersecurity Risks Rise - WSJ

But according to one cybersecurity CEO, having the right technology for defense isn't necessarily the problem. It's the humans who need to step up— .....

Read more →
Technology icon

Hard Tech

React2Shell (CVE-2025-55182)

A 10.0 critical severity vulnerablility affecting server-side use of React.js, tracked as CVE-2025-55182 in React.js and CVE-2025-66478 specifically f...

Read more →

Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer

We discovered three vulnerabilities that when chained together, allow for complete remote compromise:

Read more →

Check Point - Wrong Check Point (CVE-2024-24919)

Gather round, gather round - it’s time for another blogpost tearing open an SSLVPN appliance and laying bare a recent in-the-wild exploited bug. This ...

Read more →

Backdoor in XZ Utils allows RCE: everything you need to know - CVE-2024-3094

Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgentl...

Read more →

Loading...

The Cybersecurity Chronicles

‘The Cybersecurity Chronicles: 2024‘ pulls back the curtain on the digital threats that shaped our world last year, revealing the human stories behind the headlines. From art galleries frozen by ransomware to prison tablets hacked with a minus sign, from British Library archivists racing to protect centuries of knowledge to Spotify users meticulously curating their digital identities – these stories illuminate how cybersecurity touches every aspect of modern life.

Author Mark Nole weaves together intimate portraits of the people on all sides of the digital battlefield: the defenders working through sleepless nights to protect critical infrastructure, the victims grappling with stolen identities and lost savings, and even the attackers themselves, operating from nondescript offices with project management software and performance metrics.

Through detailed reporting and narrative storytelling, Nole reveals how 2024 became the year when cybersecurity stopped being just a technical problem and emerged as a fundamentally human challenge. Whether you’re a security professional or simply someone trying to understand our increasingly digital world, these chronicles offer an unprecedented look at how technology shapes – and sometimes betrays – our trust, our privacy, and our lives.

Mark Nole Book Cover for Cybersecurity book

Stay Updated with Cyber Security News

Get the latest cybersecurity headlines, breaking news, and expert insights delivered directly to your inbox. Stay ahead of threats and informed about the digital landscape.

Join thousands of cybersecurity professionals and enthusiasts. No spam, just valuable insights.