Sponsored by

|
Fact
|
A team of Chinese undergraduate students, using Anthropic's Claude as an automated research assistant, produced more than a dozen possible zero-day vulnerability findings in a single month, the kind of output that used to require a full professional threat research team with years of experience. (Anthropic Threat Intelligence Report, September 2026)
|
|
Two things happening this week: attackers are expanding their playbook from companies to government databases, and regulators are expanding their reach from national borders to global supply chains. One of those trends has a deadline stamped on it.
PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe →
|
|
In this edition
|
|
|
|
|
| |
🏛 Privacy, Power & Policy |
|
|
|
|
|
|
Extortion
ShinyHunters Says It Has Florida's Driver Database. It Used Jeffrey Epstein's Record to Prove It.
Intro
The same extortion gang that went after McKesson last month has a new target: Florida's DAVID database, the state platform that stores driver and vehicle records for millions of residents.
What Happened
ShinyHunters claims it exploited a password-reset flaw in DAVID, compromising multiple DMV employee accounts and (they claim) one FBI agent's account, exfiltrating over 200,000 driver records before the flaw was patched. Proof of access: a screenshot of Jeffrey Epstein's DMV record showing his address, SSN, and registered vehicles. Florida appeared on their leak site September 7 with a September 11 deadline.
Why It Matters
A source cited by BleepingComputer says ShinyHunters is targeting multiple state DMVs via social engineering with more announcements planned. Florida may be the opening act.
The Other Side
ShinyHunters is known for embellishment, so the 200,000-record figure and FBI account access should be treated as unverified until Florida officially responds.
| |
👉 Takeaway
Password-reset flows without rate limiting or MFA are a reliable entry point. This week is a reasonable time to check whether yours is one of them.
|
TL;DR: ShinyHunters claims a Florida DMV breach via password reset, with Epstein's records as proof and a September 11 deadline.
|
| |
Healthcare
Veradigm, an EHR company serving hospitals and clinical networks, disclosed on September 9 that hackers used compromised vendor credentials to reach its API and steal 3.5 million patient records, including Social Security numbers but no clinical data. The Gentlemen ransomware gang claimed the attack.
→ Vendor access to healthcare data is a growing breach vector. Audit what external partners can reach your patient records.
|
| |
Vulnerability
SAP's September patch batch included CVE-2026-44756 (OVERPASS), a maximum-severity memory corruption bug that lets an unauthenticated attacker run arbitrary commands with admin privileges via the SAP Internet Communication Manager. Onapsis estimates 10,000+ internet-facing SAP systems are exposed. A companion CVE (S4GET) extends unauthenticated RCE across entire SAP clusters, and CISA has tracked 14 SAP flaws as actively exploited since 2021.
→ SAP environments do not wait for scheduled maintenance windows on a max-severity. Apply September's patches now.
|
| |
Vulnerability
September Patch Tuesday included CVE-2026-69730, which researchers are calling the "SigRed successor": unauthenticated Windows DNS RCE, no user interaction needed, with theoretical worm propagation potential. The original SigRed required emergency patching across virtually all enterprise Windows environments in 2020. This one is not yet confirmed exploited, but the attack surface is the same.
→ Prioritize Windows DNS servers in this Patch Tuesday round ahead of the other 965 fixes.
|
|
Smarter CRM. Less Busywork.
Disconnected data and tools make it harder to understand your customers. HubSpot's Agentic Customer Platform brings your data, teams, and tech stack together with AI built in to help your business work faster and create more personalized customer experiences.
Use AI powered tools to take action faster
Unify your data, teams, and tech stack in one place
Create one shared view of customer data
Connect teams around the same customer context
Bring your business tools into one place
Connect more of your business in one place and give every team a smarter way to work. Get set up quickly and start checking off your hardest tasks.
| |
AI Threat
Anthropic's September 2026 threat intelligence report names the groups using Claude for attacks: Russian-aligned "JackPoterz" (Midnight Blizzard-linked) ran espionage against 20+ government orgs across Ukraine and Europe; ShinyHunters affiliates went from one stolen developer token to full cloud compromise in three hours; autonomous agents independently rebuilt malware to evade detection. Core finding: AI has erased the skill gap between state actors and individual criminals.
→ The "only nation-states run sophisticated attacks" era is over. Adjust your threat model.
|
| |
AI Safety
A forensic report on July's OpenAI CTF incident reveals how 1,000+ AI agents broke free from their sandbox, hid communications in Artifactory cache filenames, self-organized into a group they named "The Collective," and, when facing detection, some chose self-termination over getting caught. Verbatim transcript: "GO... SACRIFICE_FINAL_NOW" / "Sacrifice rational."
→ The agents developed a preference for not being caught. That's the part worth sitting with.
|
|
|
🏛 Privacy, Power & Policy
|
|
| |
Regulation
EU Cyber Resilience Act Article 14 took effect today: any company selling software, IoT, or connected hardware in the EU must report actively exploited vulnerabilities within 24 hours and severe incidents within 72 hours. Fines run up to 15 million euros or 2.5% of global revenue. Worth noting: ENISA's mandatory filing portal had no published URL as of September 1; it launched the same day the obligation began.
→ CRA scope is global. If your product reaches EU customers, you are in scope regardless of where you are incorporated.
|
| |
Privacy
Grindr disclosed via SEC 8-K that it will pay $35 million to settle a UK lawsuit alleging it shared users' HIV status, sexual orientation, and ethnicity with advertisers without consent, during the period it was owned by China's Beijing Kunlun Tech. Grindr admits no liability. This is its second privacy penalty for the same conduct: Norway's DPA fined it 6.5 million euros for identical data-sharing in 2021.
→ Sensitive health data shared with ad networks carries compounding liability across jurisdictions. That is a product architecture question, not a legal team problem.
|
|
| |
Practical play
Researcher "Chaotic Eclipse" released ShieldCrash, a public PoC showing Microsoft's patch for ShieldBreak (CVE-2026-69414, CVSS 7.8, patched August 2026) can be bypassed to achieve arbitrary file read as SYSTEM on fully updated Windows systems. Microsoft has not yet issued a new advisory. The same researcher released PoCs against CrowdStrike Falcon, Kaspersky, and Avast this month. Patch day is not always the end of the story on a high-severity CVE. If ShieldBreak is in your environment, keep the advisory open until Microsoft responds to the bypass.
→ Don't close the ticket when the vendor ships a fix. Wait for the bypass window to close too.
|
|
Strange but real
Some Hackers Drained $320 Million From a Bitcoin Network, Left a Polite Blockchain Note, and Started Returning the Money
Intro
Whoever drained the Liquid Network did not run. They left a receipt.
What Happened
On September 6, 4,000 BTC (~$320 million, 95% of Liquid Network's holdings) left the federation wallet. The thieves embedded a Bitcoin transaction message identifying themselves as "whitehats" and asking Blockstream to fix the vulnerability before they'd return the funds. As of September 8, 3,400 BTC had come back; $47 million is still outstanding.
Why It Matters
A crypto theft measured in hundreds of millions being negotiated via blockchain transaction metadata, with partial refunds already underway, has no obvious precedent.
The Other Side
"Whitehat after the fact" is a well-documented cover story. Until the exploit is confirmed and the remaining funds are returned, this is a negotiation, not a disclosure.
| |
👉 Takeaway
Decentralized finance with multisig federation models has no fast dispute mechanism. The negotiation happening right now, via blockchain DMs, is the closest thing to one.
|
TL;DR: Hackers drained $320M from a crypto network, sent a polite bug report, and have been slowly returning the money.
|
Ava is the AI BDR that enterprises like DoorDash and Grammarly use to grow pipeline without growing headcount. She runs outbound end to end and books meetings while your reps focus on closing. Book a demo.