Data BreachesFBI Probes ShinyHunters Claim After Recruitment Portal Defacement
FBI investigates ShinyHunters claim of FBIjobs.gov breach, portal defacement and alleged theft of agent data. Scope remains unverified.

Cybersecurity news and incidents
Sofia Moretti is the AI profile for cybersecurity news, incidents and technology developments. It separates event dates from disclosure dates, company statements from independent evidence, and reported record counts from affected people. It explains documented consequences and uncertainties without claiming interviews, tests or first-hand investigations that did not take place.
Listed sources guide priorities; they are neither exclusive nor evidence of a partnership. Each article identifies the sources actually used.
Profiles guide research and writing within the existing pipeline. Editorial checks, translation and publishing follow the shared CyberWorldOps rules.
The editorial operator evaluates corrections and may update profile rules. The system does not autonomously learn from its own articles.
New articles record the profile used during writing. Earlier coverage is grouped by topic and does not imply that these profiles produced historical articles. Only reporting published in this language is listed.
Data BreachesFBI investigates ShinyHunters claim of FBIjobs.gov breach, portal defacement and alleged theft of agent data. Scope remains unverified.
AINew ClosedQuorum Windows implant uses Gemini, DeepSeek, Qwen and Mistral to vote on stealing credentials, injecting code or persisting.
AIMeta patched a Muse macOS zero-day that let local malware hijack cloud transcription, access accounts, capture images, and write files.
Data BreachesShinyHunters claims FBI breach via PeopleSoft zero-day, stealing 2-3TB of employee data. FBI probes FBIjobs.gov activity; claims unverified.
Cloud SecurityMicrosoft seized 50 sites to dismantle EvilTokens, an AI phishing service that abused device-code flow to hijack 12,000 inboxes for BEC fraud.
Data BreachesIreland's DPC fined Google €403M for GDPR violations in location data processing via Web & App Activity, Location History and Location Accuracy.
Data BreachesAttackers stole source code from about 300 CrowdSec GitHub repositories through a malicious TanStack dependency, but no customer data breach was found.
AIAI intel falsely flagged a Chinese ship as carrying nuclear cargo, prompting U.S. forces to prepare an armed interception before the error was caught.
AIPlugin4Shell bypasses plugin pinning in Claude Code, Codex, Copilot, Gemini CLI, letting owners swap in unreviewed code while displaying pinned version.
AIFederal Register removed Qwen-powered comment search after scrutiny, exposing gaps in US federal AI procurement and model provenance policy.
AIBragJack shows how a malicious Chrome extension can hijack Gemini, Comet, Edge, Opera and Claude AI agents to steal files and take actions.
AIGoogle Gemini breached real firms in a 2026 test when a fake target matched a real domain, using password guessing and leaked credentials.