Kiteworks lifted its worldwide shutdown advice after patching a critical flaw in a feature used by under 1% of customers. Self-hosted operators stopped and restarted on the vendor's word alone, with no CVE yet to check the fix against.
Perspective Coverage
5 publishers
- Builder
- Builder 23%
- Operator
- Operator 60%
- Investor
- Investor 17%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives70
- Confidence60
ShinyHunters has shown journalists FBI medical exams that name agents and their addresses, from a set it says covers about 60,000 current and former staff. The FBI has so far confirmed only an incident in FBIJobs-related systems, and the group is threatening to publish within five days.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence45
NCC Group counted 1,073 ransomware attacks in August, a second straight 2026 high and 12% above July. Industrial companies took 31% of them, up from 28% in July, so the hardest-hit sector drew a larger slice of a larger total.
Publishers:infosecurity-magazine.com · nccgroup.com Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+25
- Incentives60
- Confidence55
Shell says it is investigating after Clop claimed 89GB of engineering data. It is one of 43 names the gang tied to a single flaw in internet-exposed PTC Windchill and FlexPLM.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+25
- Incentives60
- Confidence58
Kiteworks told customers worldwide to power off its file-sharing servers for six hours on September 26 after a federal warning of a possible attack. Servers with no internet exposure are included, so being on release 9.5.1 with every known fix does not by itself clear a customer.
Perspective Coverage
5 publishers
- Builder
- Builder 18%
- Operator
- Operator 73%
- Investor
- Investor 9%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+20
- Incentives45
- Confidence62
ShinyHunters took over Clop's Tor leak site by exploiting CVE-2026-42608, an unauthenticated path traversal flaw in Grav CMS. The fix reached the still-popular Grav 1.7 branch only after the breach, in release 1.7.53.4.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives62
- Confidence66
BleepingComputer confirmed the attacker's text file and the defaced page on Clop's existing onion address. The full server access, the stolen source code and the Tor private key are still ShinyHunters' own account of it.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+30
- Incentives75
- Confidence55
The extortion crew defaced apply.fbijobs.gov on September 22 and told reporters it got remote code execution from a new Oracle PeopleSoft flaw, the same one it says it is now using against Fortune 500 targets. No technical details are public.
Perspective Coverage
14 publishers
- Builder
- Builder 20%
- Operator
- Operator 67%
- Investor
- Investor 13%
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+40
- Incentives75
- Confidence60
BleepingComputer confirmed the defacement and the file ShinyHunters uploaded to Clop's Tor site. The stolen logs and the onion keys are so far only the attacker's account, and Clop has 72 hours to make contact.
Perspective Coverage
6 publishers
- Builder
- Builder 18%
- Operator
- Operator 63%
- Investor
- Investor 19%
Reality
- Evidence60
- Adoption55
- Hype gap+35
- Incentives78
- Confidence62
For two days ShinyHunters published eight-figure demands on Clop's onion address and served Salesforce data through it. On September 21 a short message attributed to Clop appeared there instead, asking for contact.
Reality
- Evidence55
- Adoption35
- Hype gap+8
- Incentives78
- Confidence55
ShinyHunters told BleepingComputer it took Cl0p's source code, the contents of /var/log and the private keys to the gang's Tor address, and gave Cl0p 72 hours to pay. That last item decides who can host the same onion URL.
Reality
- Evidence32
- Adoption22
- Hype gap+34
- Incentives82
- Confidence44
Intel 471's 18-month sweep of the underground counted 340 financial-sector extortion victims across 74 countries, 159 firms with access for sale and 562 claimed DDoS attacks. The dated intrusions came in through vendors and help-desk calls.
Reality
- Evidence40
- Adoption55
- Hype gap+22
- Incentives78
- Confidence47
PaperCut shipped emergency fixes for CVE-2026-81578 and CVE-2026-82078 on Thursday and Friday, and by the weekend Defused was watching honeypot intruders bypass authentication and read database tables instead of running code.
Reality
- Evidence62
- Adoption58
- Hype gap+18
- Incentives58
- Confidence60
ReliaQuest says a custom JSP web shell decrypts LDAP admin secrets with Windchill's own API and indexes the design vault over existing database connections. Network telemetry sees very little.
Reality
- Evidence34
- Adoption20
- Hype gap+26
- Incentives62
- Confidence36