LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
security

ShinyHunters Suspect Detained in Jordan Helps FBI Track Down the Group

A suspected member of the ShinyHunters cybercrime group, Saif al-Din Khader, was reportedly detained in Jordan earlier this week and is now cooperating with the FBI. Khader, who has been identified by security journalist Brian Krebs as the alleged leader of ShinyHunters operating under the alias "Rey," is said to be assisting investigators in tracking down other members of the group.

ZeroDay News ·

Source: Security Affairs

A suspected member of the ShinyHunters cybercrime group, Saif al-Din Khader, was reportedly detained in Jordan earlier this week and is now cooperating with the FBI. Khader, who has been identified by security journalist Brian Krebs as the alleged leader of ShinyHunters operating under the alias "Rey," is said to be assisting investigators in tracking down other members of the group.

Sources familiar with the matter indicate that Khader's detention occurred on Tuesday, October 2, 2026. He is reportedly providing investigators with access to his devices and digital communications, which could reveal crucial evidence and help identify former associates. The FBI has not commented on specific arrests or overseas activities but confirmed its ongoing aggressive investigation into the recent cyber incident allegedly involving ShinyHunters, stating that multiple subjects have already been arrested in collaboration with international partners.

This development follows a prior arrest in the Netherlands. Dutch police confirmed that a 24-year-old man from Amsterdam, identified by multiple sources including KrebsOnSecurity as Pepijn van der Stap, was arrested earlier in September as part of the ShinyHunters investigation. Van der Stap, known online as "Umbreon," appeared before the Rotterdam District Court on September 29. His connection to ShinyHunters stems from his use of the "Umbreon" alias and Pokémon imagery on BreachForums as early as 2021.

The "Umbreon" imagery also featured prominently in an ASCII art defacement left by ShinyHunters on the FBIjobs.gov website after a reported breach. This image is identical to one used in a 2020 HackForums defacement attributed to ShinyHunters, predating Van der Stap's "Umbreon" account. Some sources suggest that the use of this imagery in the FBI defacement might have been a deliberate attempt by "Rey" (Khader) to implicate Van der Stap, due to reported disagreements between them over control of the ShinyHunters brand and data.

The FBI Director, Kash Patel, had previously hinted at impending arrests, stating on X (formerly Twitter) on September 30, "NO SAFE HAVEN. Working with our Dutch National Police partners, the FBI helped put an alleged leader of ShinyHunters—a global cybercrime threat actor—behind bars. And we’re not done. FBI teams are working new leads RIGHT NOW. More arrests are on the table."

ShinyHunters' infrastructure experienced disruptions concurrently with Khader's reported detention. Reuters lost contact with the group's usual communication account on Tuesday, and by Wednesday, the group's dark web leak site was entirely offline. However, a new ShinyHunters leak site reportedly reappeared online on Thursday, suggesting the group remains active despite the recent arrests.

The group gained notoriety for claiming to have stolen personal data on every FBI employee. Earlier analysis of a leaked sample by Reuters indicated it contained detailed personal information, sensitive job-related data, and psychiatric and medical records. If these claims are substantiated, the incident could be comparable in scope to the 2015 OPM breach.

Interestingly, "Rey" (Khader) had reportedly informed Brian Krebs in November 2025 that he had been covertly cooperating with law enforcement since June of that year, well before any public announcements. An FBI Cyber Division official noted that arrests often increase an individual's willingness to cooperate, and seized servers can provide intelligence on other group members.

ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…

nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.