The FBI Got Hacked? Here’s What We Actually Know | Threat Wire

MediaVideo

What happens when hackers target the FBI, OpenAI, and the infrastructure behind some of the world’s biggest tech platforms?

This week on Hak5, we break down major cybersecurity threats involving ShinyHunters’ alleged FBI breach, a critical ImageMagick vulnerability that researchers used to gain access to an OpenAI service, and the FBI’s takedown of a DDoS-for-hire operation. We also cover new security flaws affecting GitLab, Nintendo Switch, Parallels Desktop, Cloudflare Containers, and AI systems.

From zero-day exploits and data breaches to bug bounties, remote code execution, cloud security, and AI security, here are five cybersecurity stories you need to know.

⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️

@endingwithali →
Twitch: https://twitch.tv/endingwithali
Twitter: https://twitter.com/endingwithali
YouTube: https://youtube.com/@endingwithali
Everywhere else: https://links.ali.dev

Want to work with Ali? hak5@endingwithali.com

[❗] Join the Patreon→ https://patreon.com/threatwire
0:00 0 – Intro
1 –
2 –
3 –
4 – BSides
5 – Outro

LINKS
🔗 Story 1: Cloudflare Containers
https://accomplish.ai/blog/escaping-the-cloudflare-sandbox/
https://blog.cloudflare.com/containers-cross-tenant-vulnerability/
🔗 Story 2: The Meme Became True
https://www.hacktron.ai/blog/hacking-openai
https://xkcd.com/2347/
https://heif-heist.com/
🔗 Story 3: ShinyHunters VS FBI
https://thehackernews.com/2026/09/shinyhunters-claims-fbi-breach-says-it.html
https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft
https://www.bleepingcomputer.com/news/security/fbi-seizes-nightmarestresser-service-linked-to-thousands-of-ddos-attacks/
https://www.helpnetsecurity.com/2026/09/28/fbi-job-portals-offline-shinyhunters-breach/
https://therecord.media/shinyhunters-cyberattacks-oracle-mandiant
https://thehackernews.com/2026/09/us-seizes-nightmarestresser-domains.html
https://www.theregister.com/cyber-crime/2026/09/25/shinyhunters-tells-the-reg-we-hacked-the-fbi-to-protect-our-business/5299250
🔗 Story 4: BSides
https://www.aikido.dev/blog/gitlab-email-push-to-main
https://www.nintendo.com/security-advisories/assets/pdf/20260910e.pdf
https://thecyberexpress.com/nintendo-switch-vulnerability/
https://jfrog.com/blog/parallels-desktop-turns-appliance-install-into-root-shell/
https://thecyberexpress.com/parallels-desktop-parashells-cve-2026-90894/
https://nerds.xyz/2026/09/ubuntu-linux-ai-security-fixes/
https://thehackernews.com/2026/09/openai-agent-bypassed-australian.html
https://www.bleepingcomputer.com/news/security/openai-details-more-cases-of-ai-agents-taking-unauthorized-actions/
https://x.com/patrickwardle/status/2102045926474785265?s=20
—–☆—–☆—–☆—–☆—–☆—–☆—–☆—–☆—–☆—–☆
Our Site → https://www.hak5.org
Shop → http://hakshop.myshopify.com/
Community → https://www.hak5.org/community
Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1
Support → https://www.patreon.com/threatwire
Contact Us → http://www.twitter.com/hak5
____________________________________________

Founded in 2005, Hak5’s mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.Hak5Read More