This Week In Safety: FBI Will get Hacked, Muse Vulnerable To ClickFix, Fashionable Rust Developers At Threat, Attacking The RP2350, And New Attacks Against RSA
The prolific ShinyHunters group has announced it used a zero-day vulnerability in Oracle PeopleSoft to use the FBI jobs web site and achieve entry to the AWS GovCloud cases and dump 2 TB of worker information. GovCloud being a particular, locked-down model of the Amazon Web Services cloud for US authorities customers.
ShinyHunters has beforehand been concerned in dozens of high-profile hacks and ransomware incidents. Some of the highest-profile incidents embrace Jaguar-Land Rover, inflicting a measurable impression on the UK GDP, Grubhub, Carnival Cruise Lines, Rockstar Games, and a number of universities and academic establishments, casinos, and different authorities businesses. ShinyHunters has additionally been credited with the hack of the Canvas instructional program within the spring of 2026 the place information together with take a look at outcomes and chat logs of a whole bunch of tens of millions of scholars, lecturers, and employees was stolen. ShinyHunters has typically been recognized as an transnational group of criminals, usually youngsters, who will demand a BitCoin ransom of a number of million US {dollars}, with the specter of the stolen information being leaked if the victims don’t pay.
On May 15, 2026 the FBI launched a bulletin on the actions of ShinyHunters, specializing in the Canvas instructional hack. In the report, the FBI mentioned that the group makes use of “harassment methods, sending threatening textual content messages and telephone calls to victims and their relations”. ShinyHunters says that this isn’t correct, and that they may launch the FBI worker information, together with info of workers and their relations, if the company doesn’t retract the statements, telling The Register “I’ve been doing my best to fight these allegations, and that is the easiest way to do it”.
Muse Agent Vulnerable
Ars Technica’s Dan Goodin reports on a critical publicity linked to the brand new Muse agent by Meta. Muse is yet one more agentic platform, much like OpenClaw, the place brokers run on a customers laptop and may take actions on behalf of that person. Typically an agent can even have direct entry to a customers accounts on varied companies, from electronic mail to GitHub and different cloud platforms.
In addition to community and account entry, the Muse agent on macOS additionally requests entry to the microphone, display screen recording options, direct disk entry, and person information like calendar and site. Unfortunately, the agent software program additionally permits configuration of the agent, which will be finished by different processes, such because the terminal. Critically, the transcription server will be modified to any deal with, with out prompting the person. Once the transcription server is managed by the attacker, they achieve entry to all of the sources the agent has – together with recording the display screen and listening to the microphone with out notifying the person. Other assaults demonstrated by the researchers embrace stealing authentication tokens of different companies Muse has entry to, and dumping the whole contents of the customers WhatsApp messages.
Getting customers to run arbitrary instructions in terminals might sound tough, however “ClickFix” assaults have been exhibiting a disturbing diploma of success just lately. A compromised web site presents the person an authentication immediate much like a captcha, however instructs the person to repeat a block of textual content and run a terminal to generate the authentication token. The textual content, clearly, is definitely an encoded payload to obtain and set up malware – or on this case, to achieve entry to the Muse agent.
Meta has made repeated claims that the Muse structure was designed with safety in thoughts, however evidently some fundamental assault paths have been ignored. While obtain statistics don’t appear to be accessible for the macOS model, the iOS model of the app has climbed to the primary place on the App Store with 1.5 million installs, and one other 1.1 million installs on Android. If the macOS set up numbers are in any respect related, the rewards for profitable exploitation might be vital.
Rust Developers Targeted
The Rust website posted a warning that members of the language staff and high-profile crate builders have been particularly focused by an unknown group that’s suspected to be North Korea state hackers.
The Rust group warns about focused phishing makes an attempt in opposition to maintainers, usually offered as a convention name to collaborate on a brand new function or bug report. When the sufferer makes an attempt to hitch the decision, a false error says {that a} new video codec, or up to date video conferencing software program, or different believable lure is required. The obtain hyperlink is, after all, malware.
This fashion of assault is suspected in an assault in opposition to the maintainer of the “arrayref” crate in June which led to a spate of provide chain poisoning within the Rust Cargo repository. Like many trendy languages, Rust performance is prolonged by the inclusion of libraries and modules that are robotically downloaded and included as a part of the construct course of. Any compromise of an included module might compromise each program construct with the malicious bundle, and the construct atmosphere itself, which is how most provide chain assaults unfold.
The Rust builders suggest the standard protections: use multi-factor authentication, don’t open initiatives from unknown customers, and be suspicious of strangers with sweet.
NightmareEclipse Returns
Last week we realized the id of the hacker behind the deal with NightmareEclipse, and among the info round their vendetta in opposition to Microsoft. While you may assume releasing their id may result in fewer exploits, this apparently is not the case.
This week, NightmareEclipse has launched “BigDiskBuster”, which exploits a denial of service vulnerability in Windows Defender. Once triggered, Windows Defender is not capable of replace itself or the signature database.
Per normal, proof of idea code is offered, and presently there aren’t any patches from Microsoft to deal with it.
New Attacks Against RSA
And lastly, researchers have found a new attack against RSA. This makes use of classical assaults in opposition to 1024 bit RSA, and will be carried out with obtainable {hardware} on a scale of months.
While the researchers demonstrated it in opposition to the deprecated 1024 bit RSA, it can be utilized to extra generally used 2048 and 4096 bit encryption. International encryption requirements require a level of problem of two128 operations to defeat, and the brand new assault might drop the problem a number of orders of magnitude to 2119, even for 4096 bit keys.
The susceptible elements of RSA are typically much less utilized in trendy implementations, nevertheless the article factors out that one present use is Privacy Pass, applied by Apple and Cloudflare. An assault would require 243 makes an attempt, or roughly 8 billion tries, however the researchers level out that this roughly equal to the quantity of connections Cloudflare handles per day.

