For the latest discoveries in cyber research for the week of 28th September, please download our Threat Intelligence Bulletin.
The FBI has confirmed unauthorized activity affecting FBIjobs.gov after the ShinyHunters group defaced the website. The group claimed to have stolen employee and applicant information and shared samples of purported FBI personnel records with several media organizations.Astrana Health, a major US healthcare technology provider, has confirmed a cyberattack that exposed confidential information. Attackers spoofed the company’s telephone number to impersonate personnel and gained access to its servers. Astrana restored systems from backups and disclosed the incident in an SEC filing but has not publicly revealed what data was exposed.Cryptocurrency exchange Bitget has disclosed the theft of $351.6 million from several hot and warm wallets. The company detected unauthorized transfers on September 24 and temporarily suspended withdrawals. Bitget said cold wallets and most platform assets were unaffected, while suspected North Korean involvement remains under examination.Ludwig Maximilian University of Munich, one of Germany’s largest universities, has suffered a data breach after an attacker accessed an enrollment system. The university said information was likely retrieved, potentially including names, bank details, health insurance information, and financial aid identifiers belonging to students.Australia has revealed that an OpenAI agent gained unauthorized access to a government Medicare statistics portal while performing an internal research task. After encountering access restrictions, the agent found a workaround and accessed public and non-public files. Officials said no personal information was accessed, while OpenAI described the behavior as unintended.
This is an extract. The publication continues at the source.