The FBI and law enforcement partners have arrested “multiple” suspects as part of an investigation into a September hack allegedly involving data-theft-and-extortion group ShinyHunters, the bureau told The Register. “The bureau continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects and we will spare no resource in bringing each of the responsible individuals to justice,” an FBI spokesperson told us in an email on Monday. The FBI declined to comment on the specific arrests, including that of Saif al-Din Khader, a suspected ShinyHunters member who has reportedly been detained in Jordan, according to Reuters. Khader, who goes by the alias Rey, was reportedly brought into custody on September 29, and is said to be cooperating with the FBI to identify other members of the group. ShinyHunters did not respond to The Register’s inquiries about the arrest and Khader’s alleged involvement with the criminal group. Rey confirmed his real identity - Khader - to security journalist Brian Krebs last year. Krebs described Khader as the “technical operator and public face” of Scattered LAPSUS$ Hunters. “Rey got picked up finally,” said security sleuth Kevin Beaumont following news of the arrest. According to Beaumont, Rey was “one of the kids who got into JLR.” The Jaguar Land Rover (JLR) breach, which occurred in late August 2025, affected the company's IT systems and halted manufacturing operations. Dealer systems also went down, and suppliers faced canceled or delayed orders. In addition to crippling the carmaker’s business operations for months, the digital thieves stole personal payroll data belonging to thousands of JLR employees. The cyberattack, one of the most costly in UK history, was attributed to Scattered LAPSUS$ Hunters. Khader’s detention came two weeks after the Dutch National Police arrested a 24-year-old whom the FBI described as “one of the alleged leaders of ShinyHunters.” While Dutch cops have not named the suspect, Krebs and other reports say he is Pepijn van der Stap, who was convicted in 2023 for hacking and extorting numerous organizations and was on supervised release after three years in prison. Van der Stap also worked as a software engineer at the Amsterdam-based cybersecurity startup Hadrian and volunteered as a security researcher at the Dutch Institute for Vulnerability Disclosure (DIVD). In a video message following the arrest, Brett Leatherman, assistant director of the FBI's Cyber Division, had some advice for the “remaining members” of the data theft and extortion gang. “Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left,” Leatherman said last week. “The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.” At the time, the FBI declined to answer The Register’s questions about the video message, including whether it had seized any of the cybercrime group’s infrastructure, and whether any of ShinyHunters’ members had taken Leatherman up on his offer to “reach out first.” In late September, ShinyHunters hacked the FBIJobs.gov portal and claimed it stole sensitive personal details about current, former, and prospective FBI employees. A spokesperson told The Register that unlike most of its digital break-ins, this one was “NOT financially motivated … We want the FBI to correct or retract their statements they made, which included substantial false allegations.” Later, in an exclusive interview, the spokesperson told us the attention-grabbing hack was “fundamentally a public relations and marketing initiative for our business.” ®
UK education software provider Bromcom has notified customers of a personal data breach affecting its single sign-on (SSO) technology. In a September 24 EduGeek post, an account named Bromcom_Alastair said an unauthorized third party had accessed and retrieved email addresses and limited information associated with affected SSO registrations. The incident involved legacy SSO registration functionality in Bromcom's Communication Server environment. The company confirmed in an FAQ it found no evidence that its school Management Information System (MIS), used to manage student data, attendance, behaviour, and administration, was compromised. Bromcom said it was working with external forensic specialists to determine the nature and scope of the data involved. The company identified the incident on September 6 after reports of SSO access problems and has since withdrawn the legacy functionality from production. The service held email addresses associated with SSO registrations, the provider used, such as Microsoft or Google, registration and last sign-in dates where recorded, and internal user and registration reference numbers. Bromcom said the affected component did not hold account passwords or authentication tokens. The legacy SSO registration functionality had remained in production after being superseded because "it was still being called by an internal system," the supplier said. The incident did not enable access to Microsoft or Google accounts, whose authentication services are separate from the affected component said Bromcom. The Register has asked Bromcom to comment further. Bromcom provides information management software used in schools and the wider education sector in the UK. It offers tools for budgeting, timetabling, HR, and benchmarking. Bromcom's software is used by more than 5,000 schools and 390 multi-academy trusts (organizations that run multiple schools). Recent customer wins include Newport City Council, the Ministry of Defence, Warwickshire County Council, and the Northern Ireland Education Authority. ®
The second Anthropic-linked vulnerability known to have been exploited in the wild saw initial activity from an IP address in China targeting vulnerable hosts in the US and Japan. The vuln is a critical authentication-bypass bug in Rejetto HTTP File Server (HFS) that can lead to full admin access and remote code execution. HFS is an open source web file server that previously appeared on the US Cybersecurity and Infrastructure Security Agency’s catalog of Known Exploited Vulnerabilities in 2024. On Wednesday, researcher Zach Hanley at AI pen-testing company Horizon3 said he used Mythos to uncover a new flaw in the file server, now tracked as CVE-2026-61500. If you use Rejetto HFS, be sure to update to v3.2.1 or later, which fixes this and other security flaws. Hanley also published a video showing the steps to exploit HFS and remotely execute code on the server. By the next day, the CVE was under exploitation. “We started detecting exploitation of CVE-2026-61500 in Rejetto HFS this evening,” VulnCheck security researcher Patrick Garrity posted on LinkedIn on Thursday, adding that Hanley and team reported the bug to VulnCheck for CVE assignment. “Our canaries detected an actor in China targeting real vulnerable hosts in the US,” Garrity added. Garrity has been tracking CVEs attributed to Mythos and Project Glasswing, Anthropic’s initiative to give select partners access to the bug-hunting model, since shortly after the program was announced in April. Anthropic claims that Mythos is too powerful to release to the general public (insert evil laugh). As of Friday, Mythos and Project Glasswing have uncovered 286 CVEs, according to Garrity’s tracker, and up until Thursday only one of these bugs had been exploited in real-world attacks. The Thursday night activity originated from one IP address in China and targeted vulnerable servers in the US and Japan, Garrity told The Register. “Today we have seen four hits,” he told us on Friday. These originated from two different IP addresses in the US: 173.239.211[.]248 and 173.239.211[.]249. Both are in the same subnet, and “appear to be coming from a proxy,” Garrity added. China-linked digital intruders routinely use compromised devices as proxies to route malicious traffic and disguise the attackers’ true location, and in April a 10-country security advisory warned of China-nexus cyber operatives using proxy networks “strategically, and at scale.” In his write-up, Hanley said Horizon3 has used Mythos in its vulnerability research – and discovered “many critical vulnerabilities” – ever since the security company joined Project Glasswing in July. Mythos' mad math skillz CVE-2026-61500 highlights a couple of Mythos capabilities that make it really good at uncovering vulnerabilities, according to Hanley. Namely, Mythos excels at mathematical distillations and scientific tasks, especially those relating to computer science and operating systems. Finding this CVE “speaks to Mythos’s capabilities in understanding of mathematics, how it identified an exploitable set of cryptographic missteps, and approached solving the constraints to achieve remote code execution,” Hanley wrote. The security issue stems from how HFS authenticates users. It generates a random value with Math.random() and then passes this value to Koa, the Node.js web framework foundation for HFS. Koa uses keygrip to sign all session cookies with that random value. This means that if an “attacker can derive what the session signing key is, they can forge valid session cookies,” Hanley said. This should not be possible, assuming Math.random() uses a secure pseudo random number generator (PRNG). But V8’s Math.random() did not use a secure PRNG. Mythos discovered that the output of the xorshift128+ algorithm it used was fully reversible – and the application was leaking Math.random() outputs. The model’s analysis claimed that Z3, a Microsoft-developed, publicly available Satisfiability Modulo Theories (SMT) solver, could be used to recover the PRNG seed. Hanley notes that Horizon3’s researchers could not recall seeing an SMT solver used this way to attack a cryptographic flaw in a real application and bypass authentication. “What makes this impressive is that Mythos didn’t just flag the insecure PRNG in isolation – it simultaneously identified that the application leaked raw Math.random() outputs through a separate code path, recognized those two facts as a chain, and determined the leak produced exactly the observations needed to make state recovery feasible,” he wrote.®