HomeCyber BalkansCyber Briefing - September 29, 2026: CyberMaterial

Cyber Briefing – September 29, 2026: CyberMaterial

Published on

spot_img

Cybersecurity Threats Evolve: Custom GPTs, Japan Cyber Attacks, and More

In recent developments within the cybersecurity landscape, alarming trends have emerged that highlight the increasing sophistication of cyber attacks. Cybersecurity analysts report that malicious Custom GPTs are now being utilized as the entry point for a multi-stage Remote Access Trojan (RAT) infection chain. This situation illustrates how threat actors are creatively tapping into trusted platforms to inflict damage.

Exploitation of Malicious Custom GPTs

The use of Custom GPT features in ChatGPT has been compromised by attackers who aim to deliver a sophisticated RAT through an intricate eight-stage infection chain. Research indicates that these attackers are utilizing fake GPT models that are hosted on OpenAI’s legitimate domain, presenting a façade of authenticity to unsuspecting users. By redirecting victims to what appears to be a legitimate Cloudflare CAPTCHA page, these malicious models trick users into executing PowerShell commands that ultimately result in the installation of a comprehensive RAT. This RAT grants hackers remote desktop access, surveillance capabilities, and persistent control over infected systems.

The cybersecurity firm Huntress has responded to at least 40 incidents involving these malicious GPTs. Although OpenAI successfully removed the original harmful versions in late September, new iterations emerged just days later, employing updated evasion techniques designed to bypass security measures.

The ShinyHunters Threat Group Expands Operations

In a separate worrying development, the cybercrime group ShinyHunters has broadened its campaign to exploit a critical authentication bypass vulnerability in Oracle PeopleSoft (CVE-2026-35273). This vulnerability allows attackers to bypass web application firewall protections by utilizing URL-encoding techniques. The group targets unpatched systems across a variety of sectors, including education, healthcare, and government. Following their attacks, they deploy web shells and backdoors to steal sensitive data.

Reports from the Google Threat Intelligence Group indicate that dozens of systems have already been compromised. Organizations significantly need to patch this vulnerability as WAF protections alone are no longer adequate. Monitoring logs for specific indicators, such as encoded requests to PSEMHUB endpoints and unusual JSP files, can be crucial for early detection.

Cyber Attacks Impacting Japan’s Transportation Sector

Meanwhile, significant cyber incidents have recently come to light in Japan, where three major transportation operators reported cyber attacks in late September 2024. While these incidents affected millions of customers, they did not disrupt the transportation services. Notably, Tokyo Metro disclosed unauthorized access to 59,000 email addresses belonging to its loyalty program. Keio Corporation, on the other hand, encountered a ransomware attack that impacted sales systems within its group companies but did not affect railway operations.

A breach at Times Car, a rental company, revealed that personal information of up to 6.6 million current and former members was exposed. This information included sensitive details such as names, addresses, and driver’s license numbers, raising significant concerns about data protection and customer privacy.

Proton Expands Microsoft 365 Migration Services

On the business front, cybersecurity and technological sovereignty are becoming increasingly intertwined. Proton has significantly expanded its Easy Switch for Business migration tool to support Microsoft 365. This service enables organizations to migrate emails, calendars, and contacts to Proton’s end-to-end encrypted platform without experiencing downtime. During the transition, synchronization between old and new systems is maintained, and the need for disruptive cutover weekends—a common pain point in migrations—is eliminated.

Given recent findings, such as 74% of European business leaders expressing concerns over potential access cuts from U.S. technology providers, Proton aims to position its Swiss jurisdiction and robust encryption as viable alternatives. This response reflects a growing trend where businesses are reconsidering their dependence on American technology firms that may be subject to extensive surveillance laws.

Law Enforcement Strikes Back Against Cybercrime

In the Netherlands, police have recently arrested a hacker known as Pepijn van der Stap, who has previous convictions for data breaches and extortion. This arrest is linked to an ongoing investigation into the ShinyHunters cybercrime group. Their operations have had a widespread impact, affecting numerous large companies worldwide. Organizations that believe they may have been targeted are advised to review their security measures carefully.

Microsoft Expands Fabric Data Analytics Platform

Lastly, in a move that aims to enhance its analytics capabilities, Microsoft has expanded access to its Fabric data analytics platform to over 425,000 Power BI customers at no extra cost. This expansion offers additional app-building tools and database capabilities, including a novel open-source SDK called Rayfin, designed to work alongside AI coding assistants like GitHub Copilot. The goal of this initiative is to blur the lines between dashboards and applications while leveraging Microsoft’s substantial existing Power BI user base.

In summary, the cybersecurity landscape is evolving rapidly with increasing sophistication, targeting various sectors and exploiting both technological vulnerabilities and human trust. It is imperative for organizations across industries to stay vigilant and proactive in strengthening their security postures to safeguard against these multifaceted threats.

Source link

Latest articles

OpenAI Discontinues GPT-6.1 Astra Amid Concerns Over Agent Misconduct

In a recent statement regarding a significant cybersecurity incident, Aviv Nahum, the co-founder and...

When the Ransom Note Appears, the Room Divides in Half

Why Documented Recovery Testing Outweighs Every Ransomware Assurance Claim Made On the night of September...

Microsoft Warns NeedyMantis Malware Allows Ongoing Network Access

New Malware Framework NeedyMantis Discovered by Microsoft Cybersecurity Researchers In a recent analysis, cybersecurity researchers...

When AI Agents Gain More Authority

Agentic AI, ...

More like this

OpenAI Discontinues GPT-6.1 Astra Amid Concerns Over Agent Misconduct

In a recent statement regarding a significant cybersecurity incident, Aviv Nahum, the co-founder and...

When the Ransom Note Appears, the Room Divides in Half

Why Documented Recovery Testing Outweighs Every Ransomware Assurance Claim Made On the night of September...

Microsoft Warns NeedyMantis Malware Allows Ongoing Network Access

New Malware Framework NeedyMantis Discovered by Microsoft Cybersecurity Researchers In a recent analysis, cybersecurity researchers...