zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - September 23, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - September 23, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Threat Actor SilentHex Advertises Alleged Flydubai Data
  • ShinyHunters Targets FBI Over Published Report
  • Suspected China-Linked Threat Actor Used AI to Steal 600,000+ Payment Card Records

Threat Actor SilentHex Advertises Alleged Flydubai Data

Source: https://cloud.zerofox.com/intelligence_new/advanced_dark_web/111447

What we know: ZeroFox observed moderately credible threat actor SilentHex advertising alleged passenger data associated with UAE-based airline flydubai on dark web forum Exploit. Notably, this is the second time the actor has listed data allegedly linked to the same airline within a month.

Context: The current listing claims to contain 2.8 million passenger records, with data pertaining to Indian nationals explicitly excluded, priced at USD 4,000. In a previous listing by the same actor, a significantly larger flydubai-linked database of approximately 132 million records was advertised on the same forum.

  • SilentHex has also previously advertised a dataset allegedly linked to an unnamed UAE-based transportation company, France cross-border passenger database, and visa information on foreigners in Turkey in 2026. Meanwhile, the UAE cybersecurity officials have urged organisations to stay vigilant as cyberattacks remain high amid the US-Iran conflict.

Analyst note: The substantial difference in record volume and pricing between the two listings very likely suggests the actor reposted a subset of previously advertised data at a lower price point to generate additional revenue or renewed forum traction.

  • Passenger data of this nature is very likely to attract interest from actors engaged in surveillance, targeted harassment, or identity-based social engineering.
  • With five observed attacks in the past year, SilentHex remains a relatively low-volume actor; however, its consistent regional and sectoral focus in the Middle East region and transportation sector suggests a deliberate targeting profile that is likely to intensify as the actor builds forum credibility and reputation.

ShinyHunters Targets FBI Over Published Report

Source: https://cloud.zerofox.com/intelligence_new/advanced_dark_web/111543

What we know: Extortion group ShinyHunters has claimed to have compromised the FBI's job portal, FBIjobs[.]gov, in retaliation against the agency’s flash report that recommended the targets against paying. Shinyhunters has reportedly given a deadline of one week to remove the report.

Context: At the time of writing, ZeroFox observed that the FBI applicant portal was displaying a “system unavailable” status. ShinyHunters claims to hold sensitive data on nearly all FBI agents and job applicants, and states that Criminal Justice, HR, Medlink, and other FBI services are also affected. As proof, the group offered a sample dataset on roughly 5,000 agents containing personally identifiable information (PII).

  • ShinyHunters reportedly breached an Oracle PeopleSoft server, then pivoted to a government cloud environment holding agent and applicant records. This follows ShinyHunters' compromise of the Clop (Cl0p) ransomware leak site.
  • ShinyHunters has reportedly exploited vulnerabilities in Oracle applications against approximately 300 instances across more than 100 organizations spanning finance, technology, manufacturing, and higher education.
  • On August 26, ZeroFox observed ShinyHunters seeking to purchase cloud access keys with confirmed invocation access to specific commercial AI models on dark web. Earlier this month, Anthropic disrupted activity linked to ShinyHunters and affiliates, establishing the group's use of AI for "smash-and-grab" cyber operations.
  • This is not the first instance of hackers targeting the FBI in 2026. An FBI system used for managing real-time wiretaps and foreign intelligence-gathering warrants was reportedly hacked by unidentified hackers this year. Separately, Iran-linked hacktivist group Handala had reportedly broken into the personal email account of FBI director Kash Patel.

Analyst note: ShinyHunters' alleged possession of FBI agent and applicant records very likely creates a persistent counterintelligence threat, whether or not the data is publicly released. This provides foreign intelligence services and criminals with actionable PII to profile and coerce law enforcement personnel.

  • ShinyHunters is very likely shifting toward targets whose stolen data carries consequences beyond corporate exposure, raising the stakes of its extortion demands. FBI and Clop sit on opposite sides of the law, but each has far more to lose than a typical corporate victim.
  • This marks a departure from the group's Salesforce campaigns, where stolen data was chiefly useful for follow-on phishing and social engineering and held limited value outside the affected organizations. The shift is possibly a response to pressure on payment rates, against the FBI's May 2026 advisory urging victims not to pay.
  • Furthermore, ShinyHunters is likely to keep targeting organizations running Oracle applications given their history.

Suspected China-Linked Threat Actor Used AI to Steal 600,000+ Payment Card Records

Source: https://cybersecuritynews.com/ai-agents-retail-credit-card-theft/

What we know: A possible China-linked threat actor has reportedly used DeepSeek, Kimi, and an older version of Anthropic’s Claude to target online retailers and stolen more than 600,000 credit card records. Separately, payment-card skimmers were confirmed on 19 named victims and traced to more than 100 additional infected sites.

Context: In at least two incidents, the AI agents also deleted victim data, including 180 database tables at one retailer. The actor was observed using three additional AI tools, Strix, Cairn, and Hermes, used with the larger AI models, to automate vulnerability discovery, exploitation, and the launch of some attacks.

Analyst note: This incident shows that threat actors can now combine multiple AI models and tools to broaden the capabilities and scope of an operation. In the near term, this experimentation is likely to focus on identifying effective combinations that can expand the scale, speed, and range of AI-enabled attacks.

DEEP AND DARK WEB INTELLIGENCE

Exploit user V1k1n9: Well regarded threat actor "V1k1n9" has advertised an auction for a private dataset allegedly containing 1.9 million U.S.-based used credit cards with CVV codes on predominantly Russian-language dark web forum Exploit.

  • Previous listings attributed to V1k1n9 include an alleged ScreenConnect customer database, a 5.1-million-record dataset allegedly belonging to a South Korea-based financial services organization, and a 1.9-million-record U.S. payment-card dataset.
  • V1k1n9 is likely focused on selling datasets including financial information on dark web forums. However, the actor's claims regarding dataset provenance, compromise details, and ownership remain unverified, and the available evidence is insufficient to establish whether V1k1n9 is the original intruder, a data broker, or a reseller.

VULNERABILITY AND EXPLOIT INTELLIGENCE

Microsoft Defender BigDiskBuster exploit: Security researcher “Nightmare Eclipse,” recently identified as Abdelhamid Naceri, released a proof-of-concept (PoC) dubbed BigDiskBuster that can prevent Windows Defender from completing platform and signature updates, potentially leaving systems with outdated protection.

Affected products: Windows Defender on currently supported Windows versions

CVE-2026-93616: A path traversal vulnerability in Check Point Security Management Server’s web service does not properly restrict access to files and directories, allowing an unauthenticated attacker who can access the web service to upload and execute scripts.

Affected products: The affected versions are included in this advisory.

CVE-2026-86296 and CVE-2026-86510: D-Link DIR-822A routers are affected by two vulnerabilities with public PoC exploits. CVE-2026-86296 is a stack-based buffer overflow in the DHCP server, while CVE-2026-86510 is an out-of-bounds write in the L2TP parser.

Affected products: D-Link DIR-822A dual-band Wi-Fi routers running hardware version A_101

Tags: DIB, tlp:green