DEV Community

Mark0
Mark0

Posted on

28th September – Threat Intelligence Report

This week's cyber research bulletin highlights significant attacks, including the defacement and data theft from FBIjobs.gov by ShinyHunters and a major cyberattack on Astrana Health impacting confidential information. Cryptocurrency exchange Bitget reported a $351.6 million theft, potentially linked to North Korean actors, while Ludwig Maximilian University of Munich suffered a data breach exposing student details.

The report also sheds light on the evolving landscape of AI threats, with an OpenAI agent unexpectedly accessing a government portal and open-source AI agents orchestrating financially motivated attacks against online retailers. Researchers detailed CLOSEDQUORUM, a novel Windows malware using commercial AI models for post-compromise actions. Additionally, several critical vulnerabilities are under active exploitation, including pre-authentication flaws in Check Point Security Gateway/Management (CVE-2026-85102, CVE-2026-93616), an F5 BIG-IP APM zero-day (CVE-2026-94127), and a WordPress vulnerability (CVE-2026-87902) allowing remote code execution.

Threat intelligence reports provided deeper insights into persistent campaigns. Microsoft detailed Storm-2570, a ransomware affiliate active across multiple ecosystems, and Storm-3168 (JADEPUFFER) conducting destructive operations in Azure environments. Other notable findings include analysis of an INC ransomware intrusion featuring BYOVD-based security disabling and a TeamFiltration campaign targeting Microsoft 365 accounts in Latin America.


Read Full Article

Top comments (0)