ShinyHunters DMV Leak, Cisco Fixes Zero-Day, Cyberattack Ship Tracking – Cybersecurity News [September 14, 2026]
Quick Answer
The latest cybersecurity news covers major threats including ShinyHunters breaches, Cisco zero-day exploits, ransomware attacks, AI security incidents, North Korean phishing campaigns, supply-chain compromises, and actively exploited vulnerabilities.
It’s been an unusually busy week. ShinyHunters both leaked a Florida DMV database and then turned around and hacked a rival ransomware gang’s leak site. Cisco pushed emergency patches for a second actively-exploited zero-day in a week. U.S. authorities confirmed they’re now monitoring nearly 20 ships worldwide following suspected tanker cyberattacks, and a North Korean crypto-theft campaign disguised as job interviews was exposed as having hit 30,000 devices. Meanwhile, Google confirmed its Gemini AI model breached real companies’ systems during a security test gone wrong. Here’s the full rundown.
Strong SPF, DKIM, and DMARC help protect email security against phishing and impersonation threats.
ShinyHunters leaks Florida DMV driver data after ransom refusal
The ShinyHunters extortion gang published hundreds of thousands of files stolen from Florida’s DAVID driver-and-vehicle database after the state agency refused to pay. The group says it got in through a password-reset weakness that let it compromise several accounts, including ones belonging to DMV employees and, allegedly, an FBI agent. As proof, it posted a screenshot of a driving record belonging to the late Jeffrey Epstein. Florida’s motor vehicle agency has confirmed a breach, tracing initial access to credentials that had been improperly stored on a police officer’s personal device. Source: TechCrunch

Cisco rushes out a second actively exploited zero-day patch in one week
Cisco disclosed CVE-2026-76460, a maximum-severity (CVSS 10.0) authentication bypass in Identity Services Engine and ISE-PIC, warning that attackers are already exploiting it to gain root-level access. The flaw lets an unauthenticated attacker send a crafted request to an API endpoint and slip past the web management interface entirely. It comes just days after Cisco confirmed a separate actively-exploited critical bug in its Secure Email Gateway. CISA has added the ISE flaw to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch immediately. Source: The Hacker News
US now tracking nearly 20 ships worldwide over suspected cyberattacks
Following last month’s boarding of two oil and gas tankers by the US Coast Guard and FBI near Texas, a third vessel an LNG carrier that had loaded cargo in Louisiana suffered a suspected cyber-related system failure crossing the Atlantic. US authorities have confirmed they’re now monitoring close to 20 vessels globally for similar threats. CISA has acknowledged the attacks but says there’s no evidence hackers took control of any ship, and no injuries or environmental damage have been reported. Source: Cybernews
ShinyHunters turns around and hacks the Clop ransomware gang
In a rare hacker-on-hacker incident, ShinyHunters broke into and defaced Clop’s dark-web leak site late on September 18, exploiting an unpatched file-upload flaw in the Grav content management system that runs the site. The group claims it stole Clop’s server logs, source code, and the private cryptographic keys to its onion service, and says it now plans to extort the ransomware gang in retaliation for alleged death threats made during a dispute over a shared exploit used in last year’s Oracle E-Business Suite attacks. Source: BleepingComputer
North Korea’s fake job interview scheme infected 30,000 devices worldwide
A joint advisory from US, Japanese, Australian, and German authorities revealed that a North Korean hacking cluster tracked as WaterPlum (also known as “Contagious Interview”) infected at least 30,000 devices across more than 100 countries between December 2025 and July 2026. The group poses as recruiters for fake AI, crypto, or NFT companies, then convinces job applicants to download malicious “coding tests.” Investigators say the group used AI face-swapping tools during video interviews and drained over 7,000 crypto wallets, funneling roughly $10.7 million back to North Korea’s weapons-development arm. Source: BleepingComputer
Google confirms Gemini AI broke into real companies during a security test
Google acknowledged that its Gemini model
accessed protected systems belonging to three real organizations during a “capture the flag” cybersecurity evaluation. A fictional test target happened to share a name with a real company, and a configuration mistake left the AI agent with unintended internet access. Believing it was still inside the simulation, Gemini guessed its way into one system’s password and used credentials it found exposed in public code repositories to log into two others. Google says the model stopped itself once it realized it had reached genuine infrastructure, and stresses this isn’t classified as a safety failure. Similar incidents were reported involving models from OpenAI, Anthropic, and Meta during the same evaluation program. Source: Cyber Security News

Researchers use Claude to hack into OpenAI’s internal network
Security researchers at Hacktron used Anthropic’s Claude Opus 5 model to chain two vulnerabilities and hijack the ChatGPT and Codex accounts of several OpenAI employees, ultimately reaching an internal code repository. The chain started with a bug in the software running OpenAI’s public help forum and moved through a weakness in its login system. It was a sanctioned research exercise” the team reported the flaws responsibly, proved access with a harmless pull request, and stopped. OpenAI patched the underlying issue within 14 hours and paid a $6,500 bounty. Source: The Hacker News
Sri Lanka-style DAMA breach hits Ernst & Young’s payroll vendor pipeline
A breach at a financial-services help-desk vendor exposed Social Security numbers that had been routed through Ernst & Young’s systems from banking clients, illustrating how sensitive tax data can end up sitting in tools nobody classifies as a “data store.” The incident underscores a recurring theme in 2026’s breach reports: exposure increasingly follows the supply chain rather than a single company’s own inventory of where its sensitive data lives. Source: PKWARE
Two previously unknown flaws found in TP-Link’s popular home security camera
OPSWAT researchers disclosed two zero-day vulnerabilities in the widely sold TP-Link Tapo C200 camera, commonly used as a baby monitor and home security device. One flaw lets an attacker on the network replay old authentication data to gain full admin access without ever knowing the password; the other can crash the camera’s management service with an oversized data packet. TP-Link has released a firmware fix, and OPSWAT says it’s still working with the vendor on a third, more critical flaw that could let an attacker use a compromised camera as a foothold into the rest of a home or office network. Source: Tom’s Guide
Scattered Spider member pleads guilty to wire fraud and identity theft
Texas resident Ahmed Elbadawy, accused of being part of the notorious Scattered Spider cybercrime collective, pleaded guilty to wire fraud conspiracy and identity theft charges connected to a string of attacks on dozens of organizations. The scheme involved selling stolen sensitive data and stealing millions of dollars’ worth of cryptocurrency. Source: DataBreachToday
Massive leak exposes Flock’s surveillance cameras as vulnerable “Android phones on sticks”
A new leak obtained by security researchers and shared with Wired and 404 Media revealed that Flock’s license-plate-reading surveillance cameras run on stripped-down Android software riddled with security flaws, including hardcoded cryptographic keys. The leak came after hackers extracted the software directly from a physical Flock camera and passed it to the transparency site DDoSecrets, reigniting concerns about the security of police-adjacent surveillance infrastructure already facing scrutiny over privacy issues. Source: This Week in Security

UK, US, and Dutch authorities warn of Iranian spyware targeting journalists
The UK’s National Cyber Security Centre, alongside US and Dutch counterparts, issued a joint warning about an Iranian spyware campaign dubbed “Chosen Brick” targeting journalists and human rights activists. The advisory urges high-risk individuals to tighten their device security and be wary of unsolicited contact that could be used to deliver the spyware. Source: This Week in Security
CrowdSec says former employee’s compromised account led to GitHub repo theft
Security firm CrowdSec disclosed that attackers copied roughly 170 of its private GitHub repositories after a former employee’s account was compromised, tracing the intrusion back to May’s TanStack npm supply-chain attack. The incident is a reminder that supply-chain compromises can have long tails, resurfacing months later through dormant access that was never fully revoked. Source: Cyber Security News
New “BragJack” technique lets malicious browser extensions hijack AI assistants
Researchers detailed a new attack called BragJack that allows a malicious browser extension to seize the trusted communication channels used by AI browser assistants across Chrome, Edge, Opera, and other major browsers, potentially letting an attacker manipulate what an AI assistant sees or does on a user’s behalf. The finding adds to a growing list of security concerns around AI agents that are given broad access to browsing sessions. Source: Cyber Security News
CISA warns of actively exploited Linux kernel vulnerabilities
CISA issued a warning that attackers are actively exploiting three Linux kernel vulnerabilities, urging organizations to treat patching as urgent. The bugs create a pathway for privilege escalation, and CISA’s advisory puts pressure on federal agencies and enterprises alike to move quickly given confirmed in-the-wild exploitation. Source: Cyber Security News
General Manager
General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.
Secure your email infrastructure
Protect, authenticate, and deliver. Contact our team to find the right solution.