LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
security

ShinyHunters hacker reportedly detained in Jordan, aiding FBI

A suspected member of the ShinyHunters hacking group, known online as "Rey," has reportedly been detained in Jordan and is cooperating with the FBI to identify and locate other members of the extortion group. The individual has been identified as Saif al-Din Khader, who was reportedly taken into custody on Tuesday. Sources indicate that Khader is assisting the FBI and international law…

ZeroDay News ·

Source: BleepingComputer

A suspected member of the ShinyHunters hacking group, known online as "Rey," has reportedly been detained in Jordan and is cooperating with the FBI to identify and locate other members of the extortion group. The individual has been identified as Saif al-Din Khader, who was reportedly taken into custody on Tuesday. Sources indicate that Khader is assisting the FBI and international law enforcement by providing access to his electronic devices and digital communications.

This reported detention follows an FBI crackdown on ShinyHunters, which intensified after the group claimed a cyberattack on the bureau in September. ShinyHunters alleged they breached FBI systems using an Oracle PeopleSoft zero-day vulnerability, subsequently moving laterally into FBI-managed AWS GovCloud systems. The attackers claimed to have stolen between 2TB and 3TB of data, including information on current and former FBI employees, job applicants, medical and psychiatric records, and internal service data. The FBI confirmed it was investigating claims of unauthorized activity but did not verify any data theft.

Prior to Khader's reported detention, Dutch police arrested a 24-year-old Amsterdam man, identified as Pepijn van der Stap (online alias "Umbreon"), on September 15 in connection with the ShinyHunters investigation. Following this arrest, the FBI publicly urged other ShinyHunters members to surrender, emphasizing that investigators were actively identifying those involved.

On the same day Khader was reportedly detained, signs of disruption emerged within ShinyHunters' operations. An alleged affiliate, who had previously communicated with media about the FBI attack and a recent Clop ransomware data breach, abruptly closed their online messaging account. Subsequently, the ShinyHunters data leak site went offline, and the group's primary representative ceased responding to media inquiries. While a new ShinyHunters data leak site appeared online on Thursday, suggesting continued operations by other members, it remains unclear if these disruptions are directly linked to Khader's detention.

Khader, under the alias "Rey," has been associated with numerous data theft and extortion incidents over the past two years. In January 2025, Rey was among four individuals who claimed responsibility for a breach of Telefónica's internal Jira ticketing system, allegedly stealing approximately 2.3GB of documents and other data. Rey was also linked to the HellCat ransomware operation and a broader series of attacks targeting Jira servers globally. In February 2025, Orange confirmed a cyberattack on its Romanian operations after Rey leaked approximately 6.5GB of stolen data, claiming to have acted independently despite being a HellCat member.

Rey was later associated with the ShinyHunters group and held administrative privileges in Telegram channels operated by "Scattered Lapsus$ Hunters." This group, which emerged in 2025, claimed to comprise former members of Lapsus$, Scattered Spider, and ShinyHunters. Scattered Lapsus$ Hunters took responsibility for a September 2025 cyberattack on Jaguar Land Rover, which caused production halts and over $220 million in losses. Rey was also linked to an earlier March 2025 breach of Jaguar Land Rover, where gigabytes of data, including Jira issues, source code, and employee information, were leaked.

In November 2025, security journalist Brian Krebs identified Rey as Saif Al-Din Khader after analyzing infostealer logs and directly communicating with Khader. Khader reportedly claimed at the time that he was distancing himself from Scattered Lapsus$ Hunters and had been cooperating with law enforcement since at least June, stating he had not engaged in corporate breaches or extortion since September. These claims could not be independently verified.

The ShinyHunters group has a history of large-scale data theft and extortion campaigns, frequently targeting Salesforce and other cloud SaaS environments. Their operations have been linked to breaches at Google, Cisco, and PornHub, often involving the compromise of third-party integration companies and the use of stolen authentication tokens to access connected SaaS environments. The group was also behind a May data-theft attack on Instructure Canvas, which led to significant platform outages and an eventual "agreement" with the threat actors to prevent data leakage. Numerous arrests have been made in connection with ShinyHunters' activities, including those related to Snowflake data-theft attacks, PowerSchool breaches, and the operation of the Breached v2 hacking forum.

ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…

nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.