Issue #217 - September 21, 2026
Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign
Source: Dark Reading
Researchers identified “Dark Sourcery,” a campaign that seeds the web with optimized fake support pages, fraudulent contact details, and phishing links so ChatGPT, Gemini, and Google AI Overview may repeat them as trusted answers. At least 374 brands were affected, underscoring the need to verify AI-provided contact and payment information.
New Check Point flaw lets hackers execute code with root privileges
Source: BleepingComputer
Check Point patched CVE-2026-91843, a critical stack-based buffer overflow affecting Security Management Server and Log Server systems. An unauthenticated attacker could achieve root-level remote code execution with low complexity and no user interaction. Customers should apply the LivePatch or restrict management access to trusted networks while monitoring failed-login alerts.
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
Source: The Hacker News
ShinyHunters claims it breached FBI systems through an undisclosed Oracle PeopleSoft zero-day, defaced the bureau’s jobs site, and stole data concerning agents, former employees, and applicants. The FBI confirmed it is investigating unauthorized activity affecting FBIJobs.gov, while the alleged vulnerability and full scope of the claimed data theft remain unverified.
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Source: The Hacker News
Researchers found Go malware distributed through two Terraform providers and two Go modules, extending a North Korea-linked package campaign into HashiCorp’s registry. The implant uses blockchain dead drops and Slack as command channels, while targeted execution checks can hinder analysis. Development teams should tightly vet providers, modules, and dependency changes.
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
Source: SecurityWeek
A Chinese threat actor exploited CVE-2026-7273, a ZyXEL GS1900 switch vulnerability, to extract hashed credentials, configurations, and network details from 996 devices in 48 countries. More than half retained factory-default credentials. CISA added the flaw to its Known Exploited Vulnerabilities catalog and required rapid federal remediation.



