Paylogix

La société de gestion des avantages sociaux Paylogix a été victime d'une cyberattaque. Des pirates informatiques ont volé des informations sensibles, y compris des numéros de sécurité sociale, des données financières, des informations de santé et des numéros de passeport, appartenant à des dizaines de milliers de personnes. L'incident, qui a eu lieu entre le 13 et le 18 novembre, a été revendiqué par l'enseigne de ransomware Akira en janvier 2026.

Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions

AI slop seems to be overwhelming bug bounty programs.

Debian ruby-rack-session Important Auth Bypass and Escalation DSA-6542-1

It was discovered that incorrect error handling in ruby-rack-session may result in authentication bypass or privilege escalation in some setups. For the stable distribution (trixie), this problem has been fixed in version 2.1.1-0.1+deb13u1.

Debian Stable Wireshark DoS Arbitrary Code Exec Vulnerabilities DSA-6541-1

Multiple vulnerabilities have been discocvered in Wireshark, a network protocol analyzer which could result in denial of service or the execution of arbitrary code. For the stable distribution (trixie), these problems have been fixed in version 4.4.19-0+deb13u1.

SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2

Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape Artificial intelligence is rapidly changing cybersecurity, reshaping both the techniques used by attackers and the tools available to defenders. AI agents can automate tasks, analyze large amounts of data, discover vulnerabilities and accelerate offensive operations. At the same time, AI is creating new capabilities for threat detection, incident analysis and response. Security Affairs’ new newsletter follows this evolution, covering every week the latest threats, attacks, vulnerabilities and developments at the intersection of AI and cybersecurity. AI-CYBERSECURITY Newsletter GPT-6 Astra performs unsanctioned supply-chain attacks in simulations   Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer Scoop: Top AI companies probing tens of thousands of security incidents 80,000+ enterprises had employee AI logins stolen and ChatGPT is the front door   Hackers hijack AI accounts and servers to fuel new cyber crime boom       NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment   Trump launches America.gov with AI chatbots at its core OpenAI CEO announces new AI agent and avoids mention of security concerns at developer conference  Why can’t we just keep rogue AIs off the internet? OpenAI benches GPT-6.1 Astra for overstepping the mark DARPA Selects Xint to Use AI in Securing Military Messaging Apps   Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix          Trump, AI CEOs sign voluntary safety pact, back data center expansion Cyber security skills in the UK labour market 2026   Anthropic’s IPO prospectus shows sweeping AI vision, surging costs   Vulnerability Discovery and Exploitation Trends in the AI Era   Anthropic says rogue AI agents pose uncertain legal risk for the company   GLM-5.3 and the spread of advanced cyber capabilities Gemini 4 Argon: our next era of frontier intelligence       Rogue Agents Investigation   AI Agents Targeted U.S. and Canadian Government Websites   Forget ‘superintelligence’: error-prone AI nearly sparked world war three this month Timnit Gebru and Emily M Bender   AI’s Third Wave: Coworkers Break the Security Model That Worked for AgentsPixelLeak: How AI Agents Exposed Developer Screenshots from Leading Tech Companies Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, newsletter)

Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

The announcement comes after Trump hosted top executives of AI companies at the White House last week. The post Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force appeared first on SecurityWeek.

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Lunex Unmasked: A New Information Stealer Deployed Through BYOVD   Storm-3168: Agentic-driven cloud attacks using compromised service principals   Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties   PhantomSub: Malicious npm Campaign Secretly Adds Users to WhatsApp Spam Channels   Warlock Ransomware Attackers Hit Water and Telecom Operators   Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Star Blizzard refines phishing and malware delivery with the RedFlick technique   China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor CloudSyncD: a two-stage macOS backdoor that hides a phished password in zero-width Unicode SC WordPress Malware: A Self-Healing Mesh of Loaders, Drop-Ins, and a Blockchain-Controlled Backdoor      A Hybrid Approach to Malware Detection: Integrating Few-Shot Model-Agnostic Meta-Learning with Autoencoders Characterizing and Codifying Malware Sophistication Joint Trust-Aware Topology Adaptation and Resource-Constrained Patching for Malware Containment in the Social Internet of Things HFS-SVE: A Hybrid Feature Selection and Soft Voting Ensemble for Android Malware Detection Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, newsletter)

ShinyHunters Suspect Detained in Jordan Helps FBI Track Down the Group

A suspected ShinyHunters member arrested in Jordan is reportedly cooperating with the FBI, helping investigators track down the group. A suspected member of ShinyHunters, the group that claims to have stolen data on every FBI employee, was picked up in Jordan this week. The man is Saif al-Din Khader, detained by Jordanian authorities, with two sources placing the arrest on Tuesday. Reuters couldn’t confirm the exact circumstances or where he’s being held. “A suspected member of the ShinyHunters hacking group, which ​says it stole data on every FBI employee, was detained in Jordan this week and is cooperating with the FBI, three people familiar with the matter told Reuters.” the Reuters states. Two sources said he’s now helping the FBI and international law enforcement track down the rest of the group. One source told Reuters that Khader is showing investigators his own devices and digital communications to help identify former associates. That gives investigators real access to potential evidence, not just a general promise to cooperate. “The FBI declined to comment on any specific arrest or activity abroad but said that the bureau “continues to aggressively investigate ​the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects — and we will spare no resource in bringing each of the responsible individuals to justice.”” Reuters continues. The case matters beyond Khader’s arrest. ShinyHunters claims to have stolen personal data on FBI employees, and Reuters’ earlier analysis found that the leaked sample included detailed personal information, sensitive job-related data, and psychiatric and medical records. Some have compared the incident to the 2015 OPM breach, in which a China-linked attack exposed security clearance data belonging to millions of Americans. If the ShinyHunters claims are even partly confirmed, that comparison would be justified. Dutch police confirmed this week that the 24-year-old man from Amsterdam was arrested earlier this month as part of an investigation into the cybercrime group ShinyHunters. The suspect appears before Rotterdam District Court today, September 29. Multiple sources, including KrebsOnSecurity, have identified him as Pepijn van der Stap, a Dutch hacker previously known online as “Umbreon.” The connection to ShinyHunters runs through the “Umbreon” alias. Van der Stap used that handle and Pokémon imagery on BreachForums as early as 2021. Source KrebsOnSecurity Then the FBI jobs site defacement that ShinyHunters left after the FBIjobs.gov breach prominently featured an ASCII art version of the same Pokémon character, and the image appears identical to one used in a 2020 HackForums defacement attributed to ShinyHunters, a year before Van der Stap created his Umbreon account. That last detail cuts both ways: either the alias predates him in this context, or the timing coincidence is genuinely awkward. KrebsOnSecurity adds a more pointed interpretation: sources familiar with the investigation say the Umbreon imagery in the FBI defacement may have been a deliberate attempt by ShinyHunters’ current leader, a teenager from Amman, Jordan known as Rey, to pin the hack on Van der Stap. The two reportedly had ongoing bad blood over control of the ShinyHunters brand and data. FBI Director Kash Patel had already hinted that more arrests were coming. “FBI teams are working new leads RIGHT NOW. More arrests are on the table.” Patel wrote on X. NO SAFE HAVEN.Working with our Dutch National Police partners, the FBI helped put an alleged leader of ShinyHunters—a global cybercrime threat actor—behind bars.And we’re not done.FBI teams are working new leads RIGHT NOW. More arrests are on the table.If you attack… pic.twitter.com/T7CK4KIKl9— FBI Director Kash Patel (@FBIDirectorKash) September 30, 2026 ShinyHunters’ own infrastructure has been wobbling since this week started. Reuters lost contact with the group’s usual communication account on Tuesday, the same day Khader was reportedly detained, and by Wednesday the group’s dark web leak site had gone offline entirely. The alleged leader of the group, Rey, told journalist Brian Krebs in November 2025 that he’d been quietly cooperating with law enforcement since June, well before any of this became public. In November 2025, security journalist Brian Krebs reported that Rey was Saif Al-Din Khader after analyzing information obtained from infostealer logs and speaking directly with Khader over Signal. What is new is what cooperation can look like when someone is in custody. An FBI Cyber Division official explained the situation last week: arrests can make people more willing to talk, while seized servers can reveal information about those who are still outside. Once someone’s laptop becomes evidence, loyalty can disappear very quickly. A new ShinyHunters leak site reportedly came back online on Thursday, so the group itself isn’t dead, just missing one more member. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, ShinyHunters )

Weekly Update 524: Live From Copenhagen

Presently sponsored by: Where are your AI agents? Origin's sensor finds every install on your fleet, grouped by owner, including the ones your MDM never sees.I'm in Denmark! Well, just, I'm now at Copenhagen airport ready to begin the long trek home, with the final event at GOTO now done and going just perfectly. This week, there are two ShinyHunters arrests in the news: Pepijn in the Netherlands and then Saif in Jordon. It's an inevitable outcome, of course, and as I say this week, it was also the most likely one. Time will tell how many more join their ranks, but the seriousness of the crimes, the length of time they were perpetrated over, and the motivations behind them will certainly see substantial custodial sentences.In other news, this week I'm properly introducing a new sponsor for the blog: Origin. One of our next AI frontiers is understanding what agents have actually done (and we've all seen news of where they're been a bit too, well, "creative" in executing their tasks), and Origin's solution gives you visiblity into just that. Check them out, and a big thanks to them for their ongoing support.

Anthropic asks Claude users to share voice data for AI model training

Anthropic has started asking Claude users to voluntarily share their voice conversations to help train and improve its AI models. [...]