Litany Of The Hacked: September 2026 Wrap-Up
Ah yes friends, it's that time. Welcome to the litany of the hacked, September 2026 edition.
There is so much noise, so much static, so little information about how AI is going to rip the guts of your SOC apart. Oh wait, maybe you have an AI SOC and then it will rip apart the guts of an attacking AI. Um, er, hold on, maybe the AIs will conspire to attack you. Or them. Who knows.
Our point is not shame, but to create shared awareness to pool resources where possible and build a sense of community. Thus, the litany now includes:
the FBI...Springfield (MA) Public Schools...city government of Winona, MN...Anne Arundel (MD) Medical Centers...City of Berlin...Novocure...Manchester, London Stansted and East Midlands airports...Pixel 6 phone systems...Chrome...Microsoft Exchange...State of Florida Department of Motor Vehicles...Liquid Network...Thomson Reuters...Eagle Mountain, UT...International Meteor Union...government of the United Arab Emirates (by Iran)...AT&T in north Texas (by Iran)...oil tankers (by Iran)...highway signs in California (by Iran)...US Department of Commerce (by OpenAI)...US Department of Education (by OpenAI)...US Securities & Exchange Commission (by OpenAI)...
Regarding the FBI breach: from the NY Times:
"In the most recent episode, ShinyHunters said it had weaponized a zero-day, or previously undiscovered, computer bug within the Oracle PeopleSoft software, an application that companies use for human resources and financial management." We note that Oracle was already on the litany.
Regarding the OpenAI intrusions -- also from the Times, & this describes the means of the intrusions (breaches?) well:
"With the Education Department, OpenAI’s technology tried to hack the website to gather data from the department’s civil rights office but failed, researchers from the A.I. research firm Transluce said. The A.I. also pulled data from the Census Bureau website, which is housed at the Commerce Department, using login credentials it found online. Separately, OpenAI’s agents shared public data from the S.E.C. website on an online forum. None of the incidents were breaches, OpenAI said, but were examples of its technology’s behaving in unexpected and concerning ways."
"Unexpected and concerning ways." Like...getting the wrong candy bar from a vending machine?
You're now in the always-on SOC era. Nation states & bots are finding ways to disrupt your operations. Managers have traditionally been responsible for monitoring people-based threats, but now leaders are also on the hook for corporate policies and procedures that because of their inadequacy can lead to cyber-attacks. And oh yeah keep an eye on that AI.
As we frequently note, what was good enough before from a talent perspective is not good enough now. You need to know what talent the new CISO or cyber-defender brings to the role.
Static can hide the truth. Change the channel.
Ask us how we can help you avoid the litany.
(image credit: Mysid, Public domain, via Wikimedia Commons)

Comments
Post a Comment