Episodes › Latest

FBI Breached, AI Malware Hijacks Servers, Defense Supplier Hit by Ransomware

19 hours ago Hornung · Bryan · Andre

FBI Breached, AI Malware Hijacks Servers, Defense Supplier Hit by Ransomware

Hackers Claim They Breached the FBI and Stole Data on Nearly Every Agent

A criminal crew says it stole data on nearly every FBI agent and job applicant through the bureau’s hiring system. The reported way in was the kind of business software your company might run. “We’re too small to be a target” doesn’t hold up.

*The tools you trust are now the attacker’s way in.*

Bryan Hornung, Randy Bryan, and Reginald Andre break down this week’s stories for executives, owners, and operators who don’t have time to track cyber news but can’t afford to be blindsided by it.

First, the FBI. The extortion group ShinyHunters claims it stole more than two terabytes of data on almost every agent and job applicant. The bureau has confirmed it’s investigating. The reported way in was a flaw in Oracle’s PeopleSoft HR software, the kind thousands of mid-size companies run. From there, the attackers reportedly jumped into the FBI’s cloud. That flaw has been disclosed since June and used all year. Any company still running an unpatched box faces the same risk. Leaked HR and applicant data could give the next attacker a ready-made kit for targeting people and their families.

Next, malware that brings its own AI. Researchers found a botnet called Carbonato that hijacks Docker servers left exposed to the internet. It installs an AI agent on the machine and lets that agent decide what to do next. The attackers didn’t build the AI. They took an open-source tool and rewrote a single 39-line instruction file to turn it hostile. Running an adaptive attack now takes little more than editing a text file. Its number-one target is your AI keys. The crew uses stolen keys to run its own bootleg AI service, so a leak costs you data and funds the attacker. The way in wasn’t a nation-state exploit. It was a server left open with no password.

Finally, a defense supplier on a ransomware leak site. A group calling itself Storm posted Applied Composites, a California company that makes composite parts for aircraft, missiles, and satellites. There’s no ransom number yet and no list of stolen files. Posting the name first puts pressure on the victim; details can follow if it stays quiet. A 500-to-1,000-person manufacturer deep in the defense supply chain is an attractive target: pressure to pay, without a Fortune 500 security budget. For a supplier, a leak-site listing isn’t just downtime. It’s a customer-trust and compliance event that can cost contracts.

None of these started with a genius hack. Trusted software left unpatched, a server left open, a supplier left under-protected. The attackers walked through the door.

• How ShinyHunters claims it breached the FBI and what data is at risk
• Why the software running your HR and cloud is now the front line
• Carbonato: the malware that installs its own AI agent to hack for it
• Why stolen AI keys are the new top prize for attackers
• How a small defense manufacturer ended up on a ransomware leak site
• Why attackers target the small supplier to reach the big customer
• What business owners should do before their name is the one on the list

Security Squawk is a weekly podcast and live stream for business owners and executives.

Support the show: buymeacoffee.com/securitysquawk
Subscribe | Like | Share

#SecuritySquawk #CyberSecurity #FBI #ShinyHunters #Ransomware #DataBreach #AI #Docker #VendorRisk #SupplyChainSecurity #MSP #BusinessRisk

Catch the full breakdown every week.