Featured image of post Cybersecurity Week in Review: September 28 – October 4, 2026

Cybersecurity Week in Review: September 28 – October 4, 2026

Cyberattacks, data breaches, zero-days, and global responses. Discover the biggest cybersecurity headlines of this week.

Major Data Breaches

ShinyHunters Suspect Detained, FBI Collaboration Intensifies

A significant development unfolded as a suspected member of the notorious ShinyHunters digital extortion group, known online as “Rey,” was reportedly detained by authorities in Jordan on September 29, 2026. Rey is said to be cooperating with the U.S. FBI and other law enforcement agencies to identify additional group members. ShinyHunters has been linked to numerous high-profile data breaches and extortion campaigns targeting enterprises worldwide. This arrest is expected to have a substantial impact on ongoing investigations and the broader cybercrime landscape1.

  • Key Details:
    • Group: ShinyHunters (linked to Scattered Spider, LAPSUS$)
    • Date of Detention: September 29, 2026
    • Law Enforcement Response: International cooperation, FBI involvement
    • Impact: Potential disruption of ongoing extortion and data leak operations

Cryptocurrency Exchange Bitget Suffers Massive Breach

Bitget, a major cryptocurrency exchange, experienced a devastating cyberattack on September 24, 2026, resulting in the theft of approximately $387.5 million from its hot and warm wallet infrastructure. The breach was detected after unauthorized transfers were observed, prompting Bitget to suspend withdrawals and initiate a comprehensive investigation. The company emphasized that cold wallets remained secure and that user funds would be reimbursed2.

  • Key Details:
    • Organization: Bitget
    • Assets Stolen: $387.5 million (hot and warm wallets)
    • Attack Vector: Backend wallet infrastructure compromise
    • Response: Withdrawals suspended, investigation ongoing

Significant Cyberattacks

Warlock Ransomware Targets Critical Infrastructure in Europe and Latin America

The Warlock ransomware group, also tracked as Gold Salem, Longlegs, and Storm-2603, continued its campaign of exploiting Microsoft SharePoint vulnerabilities to deploy ransomware. Recent attacks have targeted critical infrastructure, government, and educational organizations in Portuguese- and Spanish-speaking countries, including water utilities, telecom providers, and universities. The group is believed to be China-linked and has demonstrated the ability to disable security tools and gain deep access to victim networks1.

  • Key Details:
    • Victims: Critical infrastructure, government, education (Europe, Africa, Latin America)
    • Attack Vector: Exploitation of SharePoint vulnerabilities (old and new)
    • Impact: Ransomware deployment, security tool disablement

China-Aligned TA419 Phishing Campaigns Target U.S. AI Policy Experts

A new wave of credential phishing campaigns attributed to the China-nexus group TA419 has targeted U.S. think tanks, universities, and legal sector organizations, with a focus on AI policy experts. The campaigns impersonated prominent economists and policymakers, aiming to gather intelligence on U.S. AI policy and regulatory developments. This activity is part of broader Chinese intelligence objectives amid ongoing strategic competition with the U.S.1.

  • Key Details:
    • Threat Actor: TA419 (China-aligned)
    • Targets: U.S. AI policy experts, think tanks, universities
    • Tactics: Credential phishing, impersonation

Critical Vulnerabilities

GitLab AI Gateway Critical Flaw (CVE-2026-90970)

GitLab disclosed a critical vulnerability (CVE-2026-90970, CVSS 9.9) in its AI Gateway, which could allow a logged-in user with Duo Agent Platform access to execute arbitrary commands on the gateway. The flaw affects self-hosted gateways, and GitLab has released patches in versions 19.2.4, 19.3.2, and 19.4.1. Customers using GitLab-hosted gateways are not affected, but self-managed customers are urged to update immediately1.

  • Key Details:
    • CVE: CVE-2026-90970
    • CVSS Score: 9.9 (Critical)
    • Affected Systems: Self-hosted GitLab AI Gateways
    • Remediation: Update to patched versions

Dell Container Storage Modules (CSM) Multiple Critical Flaws

Dell released urgent security updates for its Container Storage Modules (CSM), addressing several critical vulnerabilities:

  • CVE-2026-63688 (CVSS 10.0): Missing authentication in gRPC server, allowing unauthorized access to storage backend admin credentials.

  • CVE-2026-63692 (CVSS 10.0): Authentication bypass in authorization proxy and tenant service, enabling admin-level privilege escalation.

  • CVE-2026-67269 (CVSS 9.9): Improper privilege management in the Custom Resource reconciler, allowing low-privilege attackers to escalate privileges1.

  • Key Details:

    • Products: Dell CSM for Kubernetes
    • Impact: Unauthenticated admin access, root on Kubernetes nodes
    • Remediation: Immediate patching required

Government Responses

MI5 Issues Espionage Alert on Chinese State-Linked Research Funding

The U.K.’s MI5 issued a “Security Service Espionage Alert” on September 30, 2026, warning that more than 100 U.K.-linked academics have contributed to research projects funded by the China General Technology Research Institute (CGTRI), a front for the Chinese Ministry of State Security (MSS). The research, often focused on AI, cybersecurity, and covert communications, is believed to directly enhance Chinese espionage capabilities. MI5 cautioned that some academics may be unaware of the true nature of the funding1.

  • Key Details:
    • Agency: MI5 (U.K.)
    • Concern: Chinese MSS funding of academic research
    • Focus Areas: AI, cybersecurity, covert communications

FBI Investigates Alleged Breach of Recruitment Infrastructure

The FBI is investigating claims by the ShinyHunters group of a breach affecting its recruitment infrastructure, including the defacement of the bureau’s jobs portal and theft of sensitive records belonging to employees and applicants. The incident highlights ongoing supply chain and third-party risks even for highly sophisticated organizations2.


Miscellaneous

OpenAI Parts Ways With Safety Researchers Over Data Mishandling

OpenAI terminated three members of its safety team after an internal investigation found they mishandled sensitive company information, violating established policies. The incident underscores the growing importance of internal data governance and trust in organizations developing advanced AI systems1.

The cybersecurity industry is rapidly evolving in response to the expansion of cloud infrastructure, AI, and distributed systems. Organizations are shifting toward continuous visibility, control, and risk response at scale, with a focus on identity security, telemetry management, and AI-native security operations. The increasing use of agentic AI tools is driving both new opportunities and risks, particularly in areas such as phishing, compromised accounts, and human error1.


Sources


This week’s review highlights the persistent threat of ransomware, the criticality of patching high-severity vulnerabilities, and the increasing intersection of AI, espionage, and cyber risk. Security teams are urged to remain vigilant, prioritize timely updates, and strengthen both technical and human defenses.