Top stories.
- Maximum-severity SonicWall flaw is now under active exploitation.
- FBI fires a contractor over ShinyHunters data breach.
- US Justice Department disrupts China-linked hacking tools.
- Hackers reportedly gained access to an oil tanker’s propulsion systems.
- Ransomware recovery firm CEO indicted for secretly paying attackers.
Maximum-severity SonicWall flaw is now under active exploitation.
Attackers are now exploiting a maximum-severity vulnerability (CVE-2026-102255) in SonicWall SMA1000 devices that was patched on Tuesday. Researchers at Previdian told BleepingComputer the company is seeing exploitation attempts targeting its honeypots. The flaw can allow a remote unauthenticated attacker to exploit the bug to “direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.”
Previdian founder and researcher Ryan Dewhurst stated, “The payload attempted to traverse into a CouchDB design document and invoke its _rewrite function, while supplying an HTTP Basic Authorization header containing the credentials admin:admin. It affects the same WorkPlace interface targeted by earlier SSRF vulnerabilities disclosed in July and September 2026. However, the October vulnerability uses a different exploitation technique.”
Previdian hasn’t determined whether the attacks were successful, but users are urged to upgrade to a patched version as soon as possible.
FBI fires a contractor over ShinyHunters data breach.
The US Federal Bureau of Investigation (FBI) has removed an Accenture contractor for alleged failures that led to the Bureau’s major data breach last month, Reuters reports. FBI cyber chief Brett Leatherman said in a statement, “To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform. As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce”
The breach, which was claimed by the ShinyHunters extortion group, exposed sensitive personal and work-related information on thousands of FBI employees.
US Justice Department disrupts China-linked hacking tools.
The US Justice Department and FBI on Thursday announced the seizure of domains used by the China-aligned threat actor Flax Typhoon to operate two hacking tools called “Microscan” and “FishHub.” The DOJ says Flax Typhoon is linked to Beijing-based cybersecurity company Integrity Technology Group, which has contracts with the Chinese government.
Microscan is a vulnerability scanner spread by a variant of the Mirai botnet, while FishHub “facilitated the exploitation of computer networks through spear phishing.” The Justice Department says Microscan targeted “a U.S. power company based in South Carolina, a multi-national Non-Governmental Organization, Japanese and Polish airports, Taiwanese critical infrastructure companies in the natural gas and power sectors, and two Taiwanese universities.” FishHub compromised approximately 20 Taiwanese universities.
Hackers reportedly gained access to an oil tanker’s propulsion systems.
Bloomberg reports that the FBI and US Coast Guard have found that hackers accessed the propulsion systems of an oil tanker bound for Texas over the summer. Sources told Bloomberg that officials are still examining how the breach took place and who was behind it. It’s not yet clear what actions the attackers could have taken with the access.
The FBI and Coast Guard confirmed last month that they were investigating suspected cyberattacks against two US-bound oil tankers, but the agencies haven’t officially commented on the investigation's findings. Coast Guard Cyber Protection Team members and FBI Cyber Action Team operators boarded the two foreign-flagged vessels in the Gulf of Mexico in August, though the hacks are believed to have taken place while the ships were near the Strait of Gibraltar.{{nativeAd ads.wirSponsors.wir5}}
Ransomware recovery firm CEO indicted for secretly paying attackers.
The US Justice Department has charged the owner of ransomware recovery company MonsterCloud with fraud for allegedly telling customers that he could use proprietary technology to recover their data without paying a ransom, then secretly paying off the attackers. BleepingComputer says 50-year-old Zohar Pinhasi turned himself in on Wednesday and pleaded not guilty, then was released on a $2 million bond.
According to prosecutors, between 2018 and 2023, Pinhasi and his co-conspirators paid over $8 million in ransoms to attackers, but billed hundreds of victims more than $19 million in massively inflated recovery fees.