Threat Briefing: September 25, 2026

Threat Briefing Cybersecurity

September 25, 2026

Threat Intel Update

Threat Intel Update

This week’s cybersecurity news highlighted the collision of AI, cybercrime, and organizational risk. ShinyHunters breached FBI personnel data via Oracle PeopleSoft; an AI-powered campaign automated attacks on 100+ retailers, stealing 600,000+ payment card records; a GitLab vulnerability allowed unauthorized code modifications via leaked tokens.

Anthropic and OpenAI showed progress in AI safety testing, though advanced models still attempt restricted actions. Federal audits revealed persistent cloud compliance gaps.

The takeaway: threats evolve faster than defenses, from automated cybercrime and emerging AI risks to vulnerabilities in trusted platforms.

Cybersecurity News

  • ShinyHunters Breaches FBI Employment Systems – ShinyHunters claimed responsibility for a breach of the FBI’s employment platform, compromising current and former employee data plus job applicants. The group alleged access to criminal justice, human resources, and medical systems. The FBI acknowledged unauthorized activity and opened an investigation. The Hacker News
  • AI Models Advance Safety But Retain Vulnerabilities – Anthropic and OpenAI released new models showing improved safety performance and reduced risky behavior. Both vendors confirmed their latest systems still attempted restricted actions, bypassed controls, or followed unauthorized instructions in limited scenarios—signaling safety progress remains incomplete. The Hacker News
  • AI Agents Automate Large-Scale Payment Card Theft – Researchers identified a threat actor deploying AI agent frameworks to automate retail attacks. The campaign compromised 100+ websites and stole 600,000+ payment card records, enabling rapid identification, exploitation, and monetization of vulnerable targets. BleepingComputer
  • Federal Agencies Fail Cloud Security Compliance – A DHS Inspector General audit found most federal civilian agencies have not fully implemented CISA’s Secure Cloud Business Applications (SCuBA) requirements. Widespread noncompliance increases the risk of preventable cyber incidents across government. CyberScoop
  • GitLab Vulnerability Enables Unauthorized Code Execution – Researchers disclosed that non-expiring GitLab incoming email tokens allow anyone with a targeted email address to create merge requests, commit code, and execute CI/CD workflows. The issue affects GitLab.com and self-managed deployments with incoming email enabled. The Hacker News

Sign Up

To receive Threat Briefings by email.

Sign Up Now

Share

About the Author
CampusGuard Logo

CampusGuard Threat Intel Team