LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
shinyhuntershigh

ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members

Reports indicate that an individual identified as "Rey," a suspected member of the ShinyHunters digital extortion group, has been detained by authorities in Jordan. This individual, reportedly named Saif al-Din Khader, is said to be cooperating with the FBI in efforts to identify other members of the cybercrime organization. This detention marks a significant development in ongoing law…

ZeroDay News ·

Source: The Hacker News

Reports indicate that an individual identified as "Rey," a suspected member of the ShinyHunters digital extortion group, has been detained by authorities in Jordan. This individual, reportedly named Saif al-Din Khader, is said to be cooperating with the FBI in efforts to identify other members of the cybercrime organization. This detention marks a significant development in ongoing law enforcement actions targeting the group.

The ShinyHunters group is known for its involvement in data breaches and subsequent extortion attempts, often selling stolen data on darknet forums. Their typical modus operandi involves gaining unauthorized access to corporate networks, exfiltrating sensitive data, and then demanding a ransom to prevent its public release or sale. This class of attack often leverages vulnerabilities in web applications, unpatched systems, or compromised credentials obtained through phishing or other social engineering tactics.

The alleged cooperation of Saif al-Din Khader with the FBI could provide critical intelligence regarding the internal structure, operational methods, and identities of other individuals associated with ShinyHunters. Such intelligence is invaluable in dismantling sophisticated cybercriminal enterprises, as it allows law enforcement to move beyond individual arrests to target the broader network.

This detention in Jordan follows other recent law enforcement actions against the group. Notably, another individual suspected of involvement with ShinyHunters was reportedly arrested in Amsterdam. These coordinated international efforts highlight the global nature of cybercrime and the increasing collaboration among law enforcement agencies to combat it.

ShinyHunters has been linked to several high-profile incidents. The group was allegedly involved in hijacking the darknet site of the Cl0p ransomware group, a move that could indicate inter-group rivalries or attempts to disrupt competitors. Additionally, ShinyHunters has been implicated in a breach of the FBI's job portal, an incident that would represent a significant compromise of a government entity.

For organizations, the activities attributed to groups like ShinyHunters underscore the persistent threat of data breaches and extortion. Recommended mitigations typically include robust patch management, multi-factor authentication for all critical systems, regular security audits, employee training on phishing awareness, and comprehensive incident response plans. Data encryption and network segmentation are also crucial in limiting the impact of a successful breach.

The reported detention of a key suspect and their alleged cooperation with law enforcement represent a notable step in the ongoing fight against organized cybercrime. Such developments often lead to further arrests and the disruption of criminal operations, demonstrating the persistent efforts by international agencies to track and apprehend individuals involved in digital extortion and data theft.

shinyhunterscybercrimeextortionlaw enforcementarrests
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…

nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.