The OpenSourceMalware Show #23
Dutch police arrested Pepijn van der Stap, a long-time ShinyHunters member known as Umbreon, on September 16, less than a year after he finished a prison sentence for earlier hacking, while police sep…
Dutch police arrested Pepijn van der Stap, a long-time ShinyHunters member known as Umbreon, on September 16, less than a year after he finished a prison sentence for earlier hacking, while police sep…
Anthropic's September 2026 Threat Intelligence report found that AI agents are lowering the expertise and cost required to conduct cyberattacks, widening the pool of companies attackers can profitably…
Anthropic's September 2026 threat intelligence report, "Detecting and countering misuse of AI," documents campaigns its team disrupted between December 2025 and August 2026, including a credential-har…
Anthropic disclosed that multiple threat actors, including ShinyHunters, Midnight Blizzard, and a Chinese espionage group, used its Claude model as an autonomous agent to scan 1.8 million Android APKs…
Anthropic's September 2026 threat intelligence report disclosed that hackers abused its Claude model to automate malware reconstruction and evasion, extract secrets from 1.8 million Android apps, and …
Anthropic said it disrupted "malicious use" of its Claude Haiku, Sonnet, and Opus models between December 2025 and August 2026, including attempts that could support biological and conventional weapon…
Anthropic PBC's latest threat intelligence report, covering Claude misuse it disrupted between December and August, says AI now lets individual hackers run campaigns that once required state-backed te…
Anthropic published a threat intelligence report Thursday documenting misuse of its Claude models across seven harm areas between December 2025 and August 2026, including a Russian-aligned espionage c…
Researchers at Reco have identified a new attack campaign dubbed 'City-Forum' targeting Salesforce and ServiceNow systems, exposing user data. The attacks, which bear similarities to those by the exto…
The Register reported that ADT, the most famous brand in physical security, was breached by the hacker group ShinyHunters, compromising customer data. The incident highlights ongoing vulnerabilities i…
Hackers from the extortion group ShinyHunters published data allegedly stolen from Madison Square Garden, including millions of records with personal information of customers and references to Knicks …
The U.S. Commerce Department ordered Anthropic to restrict foreign national access to its Fable 5 and Mythos 5 AI models, prompting the company to cut off access worldwide. Meanwhile, Maine disabled i…
Reco's security research team built an AI-powered agent that autonomously discovered and exploited high-severity vulnerabilities in Salesforce Experience Cloud sites belonging to major technology comp…
The hacking group ShinyHunters breached over 100 organizations by exploiting a zero-day vulnerability in Oracle PeopleSoft, according to a report. The attacks targeted unpatched systems, compromising …
The threat actor group ShinyHunters has claimed responsibility for a data breach at Charter Communications, leaking 4.9 million customer records. The stolen data includes names, addresses, and account…
Unit 42 reports a significant decline in ransomware encryption use, dropping to 78% in 2025 as threat actors shift to data theft and extortion without encryption. Driven by advanced backups, endpoint …
In 2026, adversaries are integrating artificial intelligence across the entire cyber attack lifecycle, using automated reconnaissance, AI-generated phishing, and adaptive malware to scale and customiz…
The Google Threat Intelligence Group (GTIG) has tracked an extortion campaign by the threat actor UNC6671, operating under the "BlackFile" brand, which targets organizations through sophisticated voic…
A cyberattack disrupted the online learning platform Canvas on Thursday, causing chaos at US schools and colleges as students were taking final exams. The ransomware group ShinyHunters claimed respons…
A data extortion attack by the cybercrime group ShinyHunters targeted the education technology platform Canvas, disrupting classes nationwide after the group defaced the login page with a ransom deman…