Content 

01. News Bites
  • ShinyHunters Claims FBI Breach

  • Google Fined €403 Million Over GDPR Violations

  • Microsoft and Law Enforcement Disrupt EvilTokens PhaaS Operation Linked to 12,000 Account Breaches

  • WaterPlum Malware Operation Linked to 30,000 Global Device Infections

  • Critical F5 BIG-IP APM Zero-Day Under Active Exploitation Enables Unauthenticated Remote Code Execution

02. Conclusion

Quick News Bites

ShinyHunters Claims FBI Breach

The cybercriminal group ShinyHunters has claimed responsibility for a breach of the U.S. Federal Bureau of Investigation (FBI), alleging that it obtained approximately 2 TB of sensitive data relating to current and former employees, job applicants, and several internal systems, including FBIJOBS, HR, Medlink, PEGA, CJ, and PHIRE.

The group claims the intrusion was achieved through a previously undisclosed Oracle PeopleSoft remote code execution vulnerability, although no public details or independent confirmation of such a zero-day currently exist. The FBI has acknowledged awareness of the claims and is actively investigating alleged unauthorized activity affecting FBIJobs.gov. Notably, ShinyHunters stated that the operation was not financially motivated, instead framing it as retaliation against prior FBI public statements concerning the group's activities.

The incident further reinforces ShinyHunters' reputation as a capable and resilient threat actor with a history of targeting enterprise applications, identity infrastructure, SaaS environments, and HR systems.

Google Fined €403 Million Over GDPR Violations

Google has been fined €403 million by Ireland's Data Protection Commission (DPC) following an investigation into the company's processing of users' location data between May 2018 and February 2020.

The inquiry found that Google's Web & App Activity, Location History, and Location Accuracy features failed to meet GDPR requirements relating to lawfulness, fairness, transparency, accountability, and data retention. Regulators determined that users may not have been adequately informed that their location data could be used to infer interests or influence advertising, while location information was retained longer than necessary.

In addition to the financial penalty, Google has been ordered to bring the affected processing activities into compliance within six months. From a threat intelligence perspective, the case highlights the growing regulatory and reputational risks associated with large-scale collection, processing, and retention of geolocation data, reinforcing the importance of transparent data governance, data minimisation, retention controls, and privacy-by-design principles for organisations handling sensitive user information.

Microsoft and Law Enforcement Disrupt EvilTokens PhaaS Operation Linked to 12,000 Account Breaches

EvilTokens, a sophisticated phishing-as-a-service (PhaaS) platform tracked by Microsoft as Storm-2992, has been disrupted through a coordinated operation involving Microsoft's Digital Crimes Unit (DCU), law enforcement, Health-ISAC, and other industry partners following the compromise of more than 12,000 Microsoft accounts across over 10,000 organizations worldwide.

The platform specialized in device code phishing, abusing Microsoft's legitimate OAuth 2.0 device authorization flow to obtain authentication tokens and bypass traditional credential theft and multi-factor authentication protections. Microsoft reported that EvilTokens was the first large-scale PhaaS platform to combine device code phishing with AI-powered capabilities that enabled threat actors to customize phishing lures, analyse compromised inboxes, identify high-value targets, and facilitate subsequent business email compromise (BEC) activity.

Sectors impacted included financial services, healthcare, higher education, construction, real estate, and wholesale distribution. Technical indicators associated with the activity include abuse of OAuth device-code authentication, token theft, suspicious OAuth authorisations, anomalous Entra ID sign-ins, and unauthorised access to Microsoft 365 inboxes.

WaterPlum Malware Operation Linked to 30,000 Global Device Infections

A joint advisory issued by authorities from the United States, Japan, Australia, and Germany has linked the North Korean threat group WaterPlum (also known as Contagious Interview) to a large-scale campaign that compromised at least 30,000 devices across more than 100 countries between December 2025 and July 2026, resulting in the theft of cryptocurrency assets and credentials from over 7,000 cryptocurrency wallets.

Investigators estimate that approximately $10.7 million in stolen cryptocurrency was transferred to North Korea during the period. The campaign primarily targeted software developers and IT professionals by impersonating legitimate AI, cryptocurrency, NFT, and recruiting organizations, luring victims into fake interviews or coding assessments that required downloading malicious files or executing code. Malware families attributed to the operation include BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, which facilitate credential theft, remote access, keystroke logging, data exfiltration, and cryptocurrency wallet compromise.

Authorities further warned that infected endpoints could be leveraged as a foothold into corporate environments, enabling intellectual property theft and espionage. 

Critical F5 BIG-IP APM Zero-Day Under Active Exploitation Enables Unauthenticated Remote Code Execution

F5 Networks has released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127 (CVSS 9.8), affecting BIG-IP Access Policy Manager (APM) deployments configured as an OAuth Authorization Server. According to F5, the flaw is a heap-based buffer overflow that can be exploited remotely and without authentication, allowing attackers to achieve remote code execution by sending specially crafted traffic to vulnerable virtual servers.

The vendor confirmed that the vulnerability has been actively exploited in the wild, prompting the Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities (KEV) catalog and require U.S. federal agencies to remediate affected systems. Technical indicators associated with the vulnerability include unusual OAuth authentication failures, suspicious command execution activity, and Traffic Management Microkernel (TMM) process crashes (SIGABRT).

Affected versions include BIG-IP APM 17.1.x, 17.5.x, and 21.1.x when operating in the OAuth Authorization Server role. Given the product's widespread use for VPN, identity, and application access management, successful exploitation could provide attackers with a high-value foothold for credential theft, lateral movement, and broader network compromise. 

 

Closing Summary

If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively Get in touch to find out how you can protect your organisation. 

Disclaimer

The Threat Intel Roundup was prepared by Integrity360 summarising threat news as we observe it, current at the date of publishing. It should not be considered to be legal, consulting or any other professional advice. Any recommendations should be considered in the context of your own organisation. Integrity360 does not take any political stance in the information that we share. Moreover, the opinions expressed may not necessarily be the views of Integrity360.