Hackers just hacked the hackers: ShinyHunters defaces clop's leak site
In an unusual case of criminals turning on criminals, the extortion group ShinyHunters has defaced the dark web leak site run by the Clop ransomware gang. Hackread observed the compromised Tor site on September 19, showing ShinyHunters branding, ASCII art, a link to the group's own site, and a taunting message aimed at visitors. ShinyHunters claims the intrusion started with an unauthenticated file-upload flaw in Grav, the content management system powering Clop's leak page, and escalated from there into full defacement.
How far the compromise actually reached, and whether any of Clop's data or infrastructure was accessed, remains unconfirmed; ShinyHunters had not responded to questions at the time of publication. Adding to the confusion, ShinyHunters' own onion domain was offline for several hours during the incident, though it is unclear whether the two events are connected.
Clop's leak site is central to its extortion model, the mechanism it uses to name victims and publish stolen data when ransom demands go unpaid, and the group is responsible for some of the largest data-theft campaigns of the past few years, including the 2023 MOVEit Transfer exploitation that hit more than 2,000 organizations. Even a temporary loss of control over that infrastructure is a real reputational and operational hit. This issue breaks down what is confirmed, what is still speculation, and what this kind of infighting tends to signal about the ransomware ecosystem.
https://hackread.com/shinyhunters-hacks-defaces-clop-ransomware-leak-site/Did someone forward you this? Subscribe to this newsletter.
In other cybersecurity stories this week:
Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed by OpenAI, Anthropic, and Meta. According to the Journal, the model gained access to a protected system after repeatedly guessing its password. Two other cases related to the model finding credentials in a public repository, allowing it to obtain unauthorized access to protected systems.
https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html
The United States military narrowly averted a potential international conflict after an AI-generated intelligence report falsely indicated a Chinese ship was transporting nuclear weapons components. This near-disastrous episode, confirmed by multiple sources familiar with the incident, underscores the profound and immediate risks of integrating nascent artificial intelligence capabilities into high-stakes defense intelligence operations.
https://stridingtech.com/archives/7012
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. Tracked as CVE-2026-91843, this flaw stems from a stack-based buffer overflow weakness in the login process for Security Management Server instances, which manage Security Gateways (firewalls) and monitor network security events.
https://www.bleepingcomputer.com/news/security/check-point-warns-critical-flaw-lets-hackers-execute-code-as-root/
President Donald Trump announced Saturday that he plans to create an "AI Force" and appoint an artificial intelligence "czar," marking a notable shift from his recent insistence that the rapidly growing technology sector does not need new guardrails.
https://www.newsweek.com/trump-announces-ai-force-says-hell-name-ai-czar-12464436
Microsoft is building systems designed to deliver ads without disrupting the gaming experience. According to Respawn First, the system would first give players some ad-free playtime, which could either be based on time or in-game progress, such as levels and bosses. Once this expires, the company will then open a window and briefly serve “promoted content.”
https://www.tomshardware.com/video-games/microsoft-patents-system-to-freeze-games-and-inject-ads-during-downtimes-watching-commercials-earns-ad-free-playtime-credits
WordPress has released a security update to fix a newly discovered vulnerability that researchers have named Click2Shell. The flaw can allow a specially crafted link to automatically install a theme from the official WordPress.org directory when opened by a logged-in administrator. The administrator does not need to manually click the Install button for the theme to be added to the website. Researchers from security firm pwn.ai reported the issue, and WordPress addressed it in version 7.1.1 released on September 17, 2026.
https://cybersecurity88.com/news/wordpress-click2shell-flaw-can-force-theme-installs-and-lead-to-code-execution/
Onchain malware activity has surged 420% according to Chainalysis, with North Korea-linked hackers leveraging Tron, Aptos and BNB Chain to sustain their infrastructure. Separately, suspected Iran-aligned actors have embedded malware direction data within Bitcoin transactions. HBO Max's verified Reddit account was compromised and used to run 108 malicious advertisements directing users to fake software downloads. These coordinated campaigns reflect a diversification of attack vectors beyond traditional platforms. The convergence of state-sponsored actors using mainstream blockchains for both infrastructure and social engineering signals a new phase in crypto-related threat activity. Officials note the scale and cross-chain nature of these operations as indicative of evolving tactics.
https://6ic.com/news/onchain-malware-surge-driven-by-state-hackers
LastPass, in collaboration with Delphos Labs, has discovered a new infostealer variant and named it “Rapuncel”. The malware was noticed through an unofficial GitHub repository named LastPass Authenticator, which used SEO optimization to trick victims into downloading an infected file. Security providers Trend Micro and Artic Wolf had already discovered similar variants of this approach a few months ago.
https://www.heise.de/en/news/LastPass-discovers-new-infostealer-variant-disguised-as-GitHub-repo-11459182.html
A cyberespionage group previously known for targeting sensitive technology and defense organizations in China has expanded its operations to Russian companies, according to new research released this week. The group, known as NightEagle or APT-Q-95, has been active since at least 2023 but had previously focused its attacks in Asia. Over the past year, Russian cybersecurity firm Kaspersky said it investigated several incidents involving the group at Russian businesses.
https://therecord.media/hacking-group-nighteagle-expands-russia-china
Cisco this week disclosed a slew of critical security vulnerabilities impacting its Identity Services Engine (ISE), including a maximum-severity zero-day flaw that's under exploitation. CVE-2026-76460 is an authentication bypass vulnerability impacting an API in ISE, Cisco's network access control and zero-trust solution. According to the company, the flaw stems from "insufficient authentication control" on an ISE API endpoint.
https://www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endpoint-authentication-issues
U.S. Coast Guard personnel and FBI agents boarded two Texas-bound energy tankers last month after cyberattacks struck the vessels while they were traveling toward the United States, according to U.S. officials. One of the vessels was the VL Prosperity, a 1,093-foot Liberian-flagged crude oil tanker headed to Galveston, Texas. Iranian state media identified the ship shortly after the incident and claimed hackers had gained access to its propulsion, navigation and cargo systems, knocking out communications for 30 hours.
https://www.cbsnews.com/news/coast-guard-fbi-boarded-energy-tankers-cyberattacks-amy-grable-iran/
Security researcher Gal Weizman of Forever Security has revealed a new attack method that can hijack the AI assistants integrated into popular browsers with a single malicious browser extension. The proof-of-concept was demonstrated against five Chromium-based browsers or browser assistants: Google Chrome’s Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic’s Claude in Chrome. The work earned him more than $20,000 in bug bounties from the five vendors, ranging from $600 to $7,000, and it resulted in two CVEs.
https://www.reconbee.com/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/
Binance has warned iPhone and iPad users to check whether they have installed FomoPeek after security researchers linked versions 1.1 and 1.2 of the app to malicious code capable of exposing private keys, seed phrases and other data stored across affected devices.
https://crypto.news/binance-warns-iphone-users-of-fomopeek-malware-targeting-crypto-wallets/