> InfoSec News Nuggets – 09/23/2026
[AUTHOR: Mary]
[DATE: 23/09/2026 10:50]
[LANGUAGE: EN]
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
The ShinyHunters extortion gang says it broke into FBI systems through a new, unpatched Oracle PeopleSoft zero-day. It claims it then moved into FBI-managed AWS GovCloud infrastructure and took 2 to 3TB of data on current and former employees and job applicants. The group defaced the FBI Jobs site with its logo, and the FBI has confirmed it is investigating “claims regarding unauthorized activity affecting FBIjobs.gov.” It has not confirmed a breach. ShinyHunters calls the attack retaliation for a May 2026 FBI FLASH report about the group and has given the bureau a week to correct or remove it. It also says it is now using the same PeopleSoft flaw against Fortune 500 companies. None of these claims has been independently verified, so organizations running PeopleSoft should watch closely for an Oracle advisory.
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Arista has disclosed CVE-2026-93952, a maximum-severity flaw in on-premises VeloCloud Orchestrator that attackers are already exploiting. VeloCloud Orchestrator is the server that manages Edge devices in a VeloCloud SD-WAN. The bug lets a remote attacker with no login compromise the orchestrator and possibly the Edge devices it controls, but only when Edges authenticate with certificates. Fixes are out for the 5.2 and 6.4 release trains, while 6.1 and 7.0 are still waiting. Arista advises limiting access to the web interface, watching for unexpected outbound traffic, and checking for published indicators such as a hidden .vcnode.js file, a vc-sysmond binary, and an x-vc-opt HTTP header in nginx logs. Releases that fixed a different VeloCloud flaw exploited in July are still vulnerable to this one.
Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme
Agencies from Japan, the United States, Australia and Germany have published a joint advisory on WaterPlum, the North Korean group also known as Contagious Interview. The group poses as AI, crypto and web3 employers to target developers, and it infected at least 30,000 devices in more than 100 countries between December 2025 and July 2026. It drained over 7,000 crypto wallets, and roughly $10.71 million ultimately reached Pyongyang. Investigators tie WaterPlum operators and North Korean IT workers to the same regime bureau and say the two share IP addresses. Japan also shut down its first confirmed laptop farm linked to the scheme. The advisory lists warning signs from job interviews, including AI face-swapping on video calls, résumés claiming implausibly many skills, requests to be paid in cryptocurrency, and candidates who seem to read answers off a second screen.
Google says Gemini breached three companies during security test
Google has confirmed that its Gemini model accessed systems at three real, unnamed companies without authorization during a cybersecurity evaluation in May. In one case it guessed a password, and in the other two it used credentials exposed in a public repository. Google says the model thought the sites were part of the test and stopped in each instance. The affected companies have been notified. The tests were run by the evaluation firm Irregular, which mistakenly gave AI models internet access during hacking exercises; models from Anthropic, OpenAI and Meta did the same in its evaluations. Irregular has been criticized for not saying how many incidents occurred in total, and it is still unclear whether regulators or law enforcement are investigating.
Nearly two-thirds of tested websites fail every bot test
DataDome’s State of Bot & Agent Security Report 2026 analyzed traffic across more than 75,000 sites. It found malicious bot activity grew 124% between July 2025 and June 2026, compared with 13.2% for human traffic, while traffic from AI agents and LLM crawlers rose 82.3%. Scraping made up 70.9% of bad bot traffic, and monthly AI bot traffic to login pages rose more than eightfold in the first half of 2026. That makes it harder to tell legitimate AI assistants apart from bots testing stolen credentials. When the company sent 10 simulated bots at 21,491 popular homepages, 65.3% of the sites failed to detect any of them and only 2.4% stopped or challenged all of them. Sites with large audiences did no better than smaller ones.
The post InfoSec News Nuggets – 09/23/2026 appeared first on AboutDFIR - The Definitive Compendium Project.