The Cyber Express Weekly Roundup: ShinyHunters’ FBI Breach Claim, North Korea’s WaterPlum Campaign, and the EU KIDS Act
This weekly roundup covers a brazen breach claim against the FBI’s recruitment portal, a mu 2026-9-25 14:1:55 Author: thecyberexpress.com(查看原文) 阅读量:4 收藏

This weekly roundup covers a brazen breach claim against the FBI’s recruitment portal, a multinational advisory exposing North Korea’s fake-recruiter malware operation, a sweeping EU proposal to reshape children’s access to social media, a conversation on application security in the age of AI agents, a short-lived Discord ban in the Philippines, and a multimillion-dollar hot-wallet heist at a crypto casino. 

From federal law enforcement to individual job seekers, this week’s developments show that no target is too prominent or too small.

Cybercriminals are openly taunting the agencies that pursue them, state-backed actors are turning the hiring process into an attack vector, and governments are testing how far they can push platforms on child safety, sometimes reversing course within hours. 

The Cyber Express Weekly Roundup 

Shiny Hunters Claims FBI Breach, Says FBIjobs Agent Data Exposed 

The FBI is investigating an apparent breach after the cybercriminal group Shiny Hunters claimed to have stolen personal data belonging to thousands of federal agents, with the probe centering on the bureau’s FBIjobs recruitment website. Read more… 

WaterPlum Hackers Steal $10.7M in Crypto From IT Workers 

A North Korean cyber actor group known as WaterPlum, also referred to as “Contagious Interview,” has infected at least 30,000 devices across more than 100 countries while stealing cryptocurrency from IT professionals worldwide. Read more… 

EU KIDS Act Sets New Social Media Rules for Children 

The European Commission adopted the proposal on September 18, setting out rules that would prevent children under 13 from accessing social media and establish 15 as the minimum age for minors to open accounts independently. Users aged 13 to under 15 could instead access parent-managed mini accounts with limits on social contacts and up to 60 minutes of screen time per day, while platforms would bear the responsibility of proving their services are safe for children. Read more… 

Harness’ Rahul Sood: AppSec in the Agentic Era Is About More Than Code. It’s About Authority 

In this conversation, The Cyber Express spoke with Rahul Sood, the General Manager for Application Security at Harness, who leads the company’s AppSec portfolio and focuses on building security for the AI era, integrated directly into modern DevOps workflows. The conversation centers on a shift in how security teams must think about AI agents: the risk no longer lies only in the code being shipped, but in what authority autonomous agents are granted once they operate inside production systems. Read more… 

Ban on Discord Lifted After Platform Commits to Work With DICT and CICC 

The Philippine government has lifted its ban on Discord after the platform’s representatives met with officials from the Department of Information and Communications Technology (DICT) and the Cybercrime Investigation and Coordinating Center (CICC), with the restriction removed on Thursday, Sept. 24. Read more… 

Duelbits Hit by $7 Million Hack as Crypto Stolen Across Four Blockchains 

Crypto casino Duelbits has shut down its platform after attackers took roughly $7 million from several of its wallets, with the stolen assets moved across four blockchains and mostly converted into Ether. The company says funds held in user accounts have not been affected, but it has not explained how the attackers got in or when the site will return. Read more… 

Weekly Cybersecurity Takeaway 

This week’s developments span the full spectrum of cyber risk, from a criminal group openly retaliating against the FBI over a public advisory, to a state-backed operation weaponizing job interviews against developers, to a crypto platform losing millions from the very hot wallets that keep it running. 

Meanwhile, the policy response is moving on multiple fronts: the EU is flipping the burden of proof onto platforms to demonstrate child safety by design, and the Philippines has shown how quickly a government can block, and then restore, a major platform in exchange for enforcement commitments. At the same time, security leaders are warning that AI agents are introducing an entirely new question of who, or what, holds authority inside enterprise systems. 

Taken together, the stories point to an increasingly confrontational threat landscape, where attackers are bolder, trust-based processes like hiring are being exploited at scale, and institutions are experimenting with more aggressive levers to hold platforms and adversaries accountable. 


文章来源: https://thecyberexpress.com/weekly-roundup-shiny-hunters-fbi-waterplum/
如有侵权请联系:admin#unsafe.sh