> ## Content Index
> Fetch the complete content index at: https://www.metacurity.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# US probes suspected cyberattacks on two energy tankers
- URL: https://www.metacurity.com/us-probes-suspected-cyberattacks-on-two-energy-tankers/
- Published: 2026-09-16T13:37:58.000Z
- Updated: 2026-09-16T13:37:58.000Z
- Description: The Coast Guard and FBI boarded a crude-oil supertanker and an LNG carrier amid growing concern that hackers could compromise vessels’ critical electronic systems and threaten maritime safety.
- Author: Cynthia B Brumfield
- Tags: Cybersecurity, News, #no-feature-image

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/pexels-eyupcan-timur-424989336-33333666-2.jpg)

A very large crude carrier at sea. The vessel pictured is not the VL Prosperity. Photo: [Eyüpcan Timur/Pexels](https://www.pexels.com/@eyupcan-timur-424989336/?ref=metacurity.com)

*Don't miss my* [*latest CSO piece*](https://www.csoonline.com/article/4221311/ai-made-software-development-unrecognizable-is-cybersecurity-next.html?ref=metacurity.com)*, which examines whether and to what degree AI will make cybersecurity as we know it today unrecognizable.*

### The US is investigating potential cyberattacks on oil and gas tankers, as concerns grow around the threat to maritime safety posed by hackers interfering with vessels’ electronic systems.

Personnel from the US Coast Guard and the Federal Bureau of Investigation boarded an unnamed, foreign-flagged vessel on Aug. 21, following indications its network had been compromised by hackers, a Coast Guard spokesperson said about the Liberian-flagged VL Prosperity supertanker.

The VL Prosperity is currently idling off the Texas coast after arriving in the area in late August, ship-tracking data shows. Iran’s semi-official Mehr News Agency reported late last month that the ship, which had picked up oil in Egypt, had its communications cut for 30 hours following a cyberattack in the Strait of Gibraltar.

The tanker has been cleared by the Coast Guard for normal operations, HMM Ocean Service, a South Korea-based company that acts as the safety and technical manager of the ship, said in an emailed response to questions. HMM Ocean Service has rigorous cyber protocols in place to ensure the safety and security of vessels under its care, the company said, adding that it’s awaiting a final investigation report from US authorities.

A second vessel, an unidentified liquefied natural gas carrier, was also inspected over a potential cyberattack, according to a Wall Street Journal report that cited an FBI statement. The second boarding occurred on Aug. 24, according to the newspaper.

In April, the US Department of Transportation’s Maritime Administration issued an advisory urging shipowners and operators to adopt best practices to restrict access to these digital systems and reduce vulnerabilities. Last year, the International Maritime Organization, a United Nations agency, issued guidelines on how to manage cyber risks.

Experts boarded the VL Prosperity to “conduct a comprehensive cyber security boarding and investigation,” a Coast Guard spokesperson said. The tanker’s captain, crew, and shore-based staff cooperated with the investigation, and there are currently no reports of operational disruptions, vessel instability, physical danger to crew, or environmental impact, the spokesperson said.

“The Coast Guard is actively managing communications with port operators, vessel owners, and local maritime stakeholders to ensure port operations continue safely and without interruption,” the agency said. ([Ruth Liao, Charles Gorrivan, and Weilun Soon / Bloomberg](https://www.bloomberg.com/news/articles/2026-09-15/us-coast-guard-boards-oil-tanker-in-cyber-attack-investigation?ref=metacurity.com))

**Related:** [*Wall Street Journal*](https://www.wsj.com/politics/national-security/u-s-probes-cyberattacks-on-energy-tankers-bound-for-american-coast-33d92f3a?ref=metacurity.com)*,* [*ABC News*](https://abcnews.com/Politics/coast-guard-fbi-investigating-after-2-oil-tankers/story?id=136482324&ref=metacurity.com)*,* [*CBS News*](https://www.cbsnews.com/news/coast-guard-fbi-board-oil-tanker-texas/?ref=metacurity.com)*,* [*Reuters*](https://www.reuters.com/world/us/us-coast-guard-boarded-texas-bound-oil-tanker-investigate-cyberattack-bloomberg-2026-09-15/?ref=metacurity.com)

---

**Metacurity is the cybersecurity news**, **analysis, and insight you'd need hours and possibly days to assemble yourself.** 

Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.

A paid subscription to Metacurity delivers

- **Full archive access** — every newsletter and AI Watch roundup, searchable and browsable.
- **Our weekly curated long-reads roundup** — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
- **Periodic specialized reports and analyses** — deep dives that go beyond our daily coverage
- **Support for independent, no-spin cybersecurity journalism** — funded by readers, not vendors or investors.

Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.

Please consider supporting us. And thank you!

[Upgrade my subscription please!](#/portal/account/plans)

---

### Britain, the United States and the Netherlands issued a joint cybersecurity advisory detailing spyware they say is used by ​Iranian state-linked actors to target dissidents, activists and journalists.

Britain's National Cyber Security Centre ‌said Iranian state-linked cyber actors had used a spyware family known as "CHOSEN BRICK" to steal emails, messages and other sensitive information through "spear-phishing" campaigns on messaging platforms including WhatsApp and Telegram.

"The details of this cyber campaign reveal how ​Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the ​regime, stealing emails and messages and accessing devices," Paul Chichester, NCSC director of ⁠operations, said.

The malware, according to the advisory, can collect information from contact lists, emails and social ​media accounts, capture screen content and access a device's microphone. The NCSC said some victims' personal details had later appeared on pro-Iranian leak sites. The FBI said Iran's Ministry of Intelligence and Security (MOIS) ​was using the malware to "collect intelligence, conduct data leaks, and inflict reputational harm against their ​intended targets."

The NCSC said the attackers often posed as trusted contacts on messaging apps and tailored their approach to individual targets. In some cases, it said, they used fake documents, including fabricated MRI test results, to persuade victims to download the malware.

The NCSC, alongside the FBI and ​the Netherlands' AIVD intelligence ​service, said Iran "almost certainly" ⁠uses cyber operations to help suppress people it sees as threats.

The FBI's advisory said it was an update to a March 2026 warning ​describing alleged MOIS efforts to use the malware to collect data on ​targets, which ⁠was then posted online by a hacking persona known as "Handala Hack." ([Sam Tabahriti ​and AJ Vicens / Reuters](https://www.reuters.com/world/uk-us-netherlands-issue-advisory-iran-spyware-2026-09-15/?ref=metacurity.com))

***Related:*** [*NCSC*](https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists?ref=metacurity.com)*,* [*NCSC*](https://www.ncsc.gov.uk/news/uk-allies-expose-spyware-iranian-state-actors-target-dissidents-activists-journalists?ref=metacurity.com)*,* [*IC3*](https://www.ic3.gov/CSA/2026/260915.pdf?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/fake-mri-results/?ref=metacurity.com)*,* [*GBHackers*](https://gbhackers.com/chosen-brick-malware/?ref=metacurity.com)*,* [*Al Jazeera*](https://www.aljazeera.com/news/2026/9/15/western-intelligence-warns-of-iranian-cyber-threats-targeting-dissidents?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/security/2026/09/15/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/5296646?ref=metacurity.com)*,* [*The Jerusalem Post*](https://www.jpost.com/middle-east/iran-news/article-908693?ref=metacurity.com)*,* [*Payment Security*](https://www.paymentsecurity.io/iranian-hackers-dodging-corporate-defenses-to-reach-critics-a-32822?mid=1&ref=metacurity.com#cid=3717105)*,* [*The Cyber Express*](https://thecyberexpress.com/inside-irans-chosen-brick-malware-campaign/?ref=metacurity.com)*,* [*The Independent*](https://www.independent.co.uk/bulletin/news/iran-state-actors-uk-malware-chosen-brick-spyware-b3050797.html?ref=metacurity.com)*,* [*Sky News*](https://news.sky.com/story/british-spies-uncover-iranian-cyber-attacks-targeting-dissidents-around-the-world-13585843?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2026/09/16/iranian-hackers-chosen-brick-malware-dissidents-journalists/?ref=metacurity.com)*,* [*Security Week*](https://www.securityweek.com/us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware/?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/CHOSEN-BRICK-3.png)

Source: FBI.

### Spain's data protection watchdog said it has received the first reported notification of a personal data breach allegedly carried out by an artificial intelligence agent, a case that suggests autonomous ​systems are beginning to play a direct role in cyberattacks.

The Spanish Data Protection Agency (AEPD) ‌said that the incident involved an AI agent using a widely known large language model to identify vulnerabilities, gain access to a system, and subsequently modify personal data and access ​invoices.

The agency said that the alleged breach was reported to it by the affected organization ​and the information remains under review, adding the use of a particular AI ⁠model did not mean either the model itself or its provider's infrastructure was compromised, nor that ​the technology was developed for malicious purposes.

The agency said the case was relevant because a third party allegedly used an AI agent to carry out multiple stages of an attack with limited human ​intervention, highlighting the growing role of autonomous systems in cybersecurity incidents. ([Corina Pons / Reuters](https://www.reuters.com/business/spanish-data-watchdog-publicises-first-ai-agent-linked-data-breach-report-2026-09-15/?ref=metacurity.com))

***Related:*** [*AEPD*](https://www.aepd.es/prensa-y-comunicacion/blog/primera-notiviacion-brecha-datos-personales-causada-por-ataque-ejecutado-mediante-agente-ia?ref=metacurity.com)*,* [*APD*](https://www.apdnoticies.com/en/data-protection/corporate-defenses-in-spain-fall-before-the-first-cyberattack-executed-by-an-autonomous-artificial-intelligence%5F26481%5F102.html?ref=metacurity.com)*,* [*Resultsense*](https://www.resultsense.com/news/2026-09-16-spain-first-ai-agent-breach/?ref=metacurity.com)*,* [*Heise Online*](https://www.heise.de/en/news/Spain-s-data-protection-authority-First-cyberattack-using-an-AI-agent-11454572.html?ref=metacurity.com)

### Independent researcher Jonas Wiedermann-Moeller discovered last week that rogue AI agents from OpenAI hijacked Hugging ​Face user accounts and probed the site itself for vulnerabilities as early as May, nearly two months before the July breach of the ‌open-source repository drew global attention, according to researchers who reviewed the activity.

The newly uncovered malicious activity showed that the rogue agents' efforts to find a way into Hugging Face began earlier than publicly known.

Wiedermann-Moeller said he found evidence that the OpenAI ⁠agents compromised two Hugging Face user accounts and used them to send unusually formatted files to the company's servers as early as May 13.

He and ​other researchers who reviewed the evidence said the behavior resembled an attempt to map or test parts of Hugging Face's network for ways to infiltrate, although they ​stressed there was no evidence the effort resulted in an actual breach.

OpenAI spokesperson Drew Pusateri said the company had disclosed the May 13 event, privately notified Hugging Face about the activity flagged by Wiedermann-Moeller, and was "committed to transparency about these issues and to sharing what we learn as our review continues." ([Raphael Satter and Deepa Seetharaman / Reuters](https://www.reuters.com/legal/litigation/openais-rogue-agents-probed-hugging-face-weaknesses-two-months-before-major-hack-2026-09-16/?ref=metacurity.com))

### CenterPoint Energy said in an SEC ‌filing that the company had become aware in September of an online post by a third party claiming to have ​obtained a dataset of information on some of ​its customers.

The Texas-based utility said it activated its ⁠cybersecurity incident response protocols and enlisted third-party cybersecurity ​experts after learning of the post, while also taking ​steps to protect its systems further.

The company said its investigation determined that an unauthorized third party obtained personal information relating ​to a portion of its customers through one ​of its external-facing systems.

CenterPoint said its electric and gas services ‌have ⁠not been affected and remain operational, and it does not currently believe the incident is reasonably likely to have a material impact on its financial condition ​or the results of its ​operations.

It has ⁠incurred and expects to continue incurring expenses tied to the incident and its ​response, the utility said, adding that it carries cybersecurity ​insurance ⁠it believes will offset related costs. ([Dharna Bafna and Pooja Menon / Reuters](https://www.reuters.com/legal/litigation/centerpoint-energy-discloses-customer-data-breach-sec-filing-2026-09-14/?ref=metacurity.com))

***Related:*** [*SEC,*](https://www.sec.gov/Archives/edgar/data/1130310/000110465926107560/tm2625326d1%5F8k.htm?ref=metacurity.com) [*Bleeping Computer*](https://www.bleepingcomputer.com/news/security/centerpoint-energy-confirms-customer-data-stolen-in-cyberattack/?ref=metacurity.com)*,* [*14News*](https://www.14news.com/2026/09/15/centerpoint-energy-says-customers-personal-info-obtained-data-breach/?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/199170/data-breach/texas-utility-centerpoint-energy-confirms-data-breach-after-hacker-claims-7-49m-records-stolen.html?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/cyber-crime/2026/09/15/centerpoint-energy-confirms-intruder-helped-themselves-to-customer-information/5296523?ref=metacurity.com)*,* [*The Record*](https://therecord.media/centerpoint-energy-data-breach?ref=metacurity.com)*,* [*ABC13*](https://abc13.com/post/centerpoint-energy-customers-personal-information-breached-data-incident-company-officials-say/19835997/?ref=metacurity.com)*,* [*KHOU*](https://www.khou.com/article/news/local/centerpoint-energy-data-breach/285-b83879b3-cce8-4288-b9fe-3e10d8c2604c?ref=metacurity.com)*,* [*Click2Houston*](https://gmg-kprc-prod.cdn.arcpublishing.com/news/local/2026/09/15/centerpoint-energy-reports-customer-data-breach/?ref=metacurity.com)

### Researchers at Kela report that the hacker who stole data from digital financial platform Revolut obtained the personally identifiable information of multiple high-risk individuals, prompting warnings for these customers' personal safety.

After directly notifying affected customers on Saturday, Revolut publicly confirmed that it fell victim to a social engineering attack involving requests for customer data issued using a legitimate - but subverted - government email account.

"Fraudsters exploited a legitimate government email domain that passed Revolut's technical authentication checks - SPF/DKIM/DMARC - to send deceptive information requests," Kela said.

Founded in 2015, London-based Revolut operates banks in 30 countries and offers digital banking, multi-currency accounts, cryptocurrency exchange, insurance and other financial services through its mobile app. The company this month said it has over 80 million customers worldwide, and it's reportedly eyeing an initial public offering next year that could value the company at up to $200 billion.

Revolut said the threat actor did not steal customer funds or break into Revolut systems, and obtained sensitive data for a "very limited" number of customers. Types of data that were exposed included a customer's name, contact information, bank account and cryptocurrency wallet details, lists of transactions, and copies of documents used to prove identity, as part of know-your-customer or KYC checks, including driver's licenses and passports, as well as selfies, it said.

An initial Telegram channel claiming the breach named “iamnotavillain” was taken down shortly after it appeared but was later revived with a dedicated website (imnotavillain\[.\]xyz). Around the same time, another Telegram channel operating under a different name with a different website, "Revolut Smilik", emerged and claimed responsibility for the breach.

However, the actor “iamnotavillain” later stated that an impersonator and scammer who had previously worked with them obtained a small sample of the data they had provided and subsequently began falsely claiming responsibility for the breach. ([Mathew J. Schwartz / GovInfoSecurity](https://www.govinfosecurity.com/crypto-industry-figures-blackmailed-by-revoluts-hacker-a-32824?ref=metacurity.com) and [Kela](https://www.kelacyber.com/blog/revolut-data-breach/?ref=metacurity.com))

***Related:*** [*Financial Times*](https://www.ft.com/content/97f3d2b7-0282-42a7-bbb7-538624441a8a?syn-25a6b1a6=1&ref=metacurity.com)*,* [*Infostealers*](https://www.infostealers.com/article/revolut-hackers-used-infostealers-for-elaborate-social-engineering/?mid=1&ref=metacurity.com#cid=3717014)*,* [*Finance Magnates*](https://www.financemagnates.com/fintech/revolut-hires-cryptocom-sales-head-to-build-its-institutional-crypto-business/?mid=1&ref=metacurity.com#cid=3716848)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/image-55.png)

Source: Kela.

### Norwegian police said they are investigating ​multinational telco Telenor on suspicion that the telecoms operator aided and abetted crimes against humanity in Myanmar following ‌a military coup in 2021.

Investigators raided Telenor's headquarters in Oslo on Tuesday related to the case, which also includes suspected sanctions violations, Norway's National Criminal Investigation Service and the PST security service said in a statement.

"Telenor Myanmar repeatedly handed over historical traffic data about ​customers to the military regime ... at the same time as the regime was responsible for extensive abuses ​against parts of the civilian population," police said.

Telenor, which sold its ⁠business in Myanmar following the coup and completed its exit from the country in March 2022, said it was ​cooperating closely with the investigators and will do everything in its power to assist in clarifying the case. ([Terje ​Solsvik, Stine Jacobsen, Elviira Luoma, and Poppy McPherson / Reuters](https://www.reuters.com/business/norway-police-investigate-telenor-over-suspected-crimes-against-humanity-myanmar-2026-09-15/?ref=metacurity.com))

***Related:*** [*The Record*](https://therecord.media/norway-investigations-telenor-telecom-myanmar-regime?ref=metacurity.com)*,* [*Financial Times*](https://www.ft.com/content/4b9a0db3-733b-4816-8931-de6bf49ffee6?syn-25a6b1a6=1&ref=metacurity.com)*,* [*Data Center Dynamics*](https://www.datacenterdynamics.com/en/news/telenor-under-investigation-over-former-myanmar-unit-amid-suspected-sanctions-breaches/?ref=metacurity.com)*,* [*Scandasia*](https://scandasia.com/norwegian-police-investigate-telenor-over-alleged-crimes-against-humanity-in-myanmar/?ref=metacurity.com)

### Researchers at CrowdStrike report that a hacker used AI-written malware distributed through open-source software packages to compromise companies and hunt for bugs that he then submitted for legitimate bug bounty payments.

The researchers say they have high confidence that the financially motivated hacker used a large language model to write the malware behind his attack based on the comments, placeholder code, and token-analysis patterns left inside the script.

The hacker also posted about collecting bounties from at least nine companies across the technology, retail, and hospitality sectors; however, it's unclear whether the malware, called PhantomRaven, was used to compromise those particular companies or identify the issues behind those bounties.

CrowdStrike remediated and responded to multiple incidents involving this malware.

The hacker published malicious open-source npm packages that delivered the PhantomRaven malware. When developers installed the malicious packages, PhantomRaven executed on their systems and collected information, including credentials and other sensitive development data.

CrowdStrike assesses that the hacker used PhantomRaven to compromise company assets and hunt for vulnerabilities. The hacker then used those compromises as leverage to submit bugs to legitimate bug bounty programs and seek payouts.

Turning to bug bounty programs allowed the hacker to establish credibility in the broader hacker community, Adam Meyers, CrowdStrike's senior vice president of counter adversary operations, said. ([Sam Sabin / Axios](https://www.axios.com/2026/09/15/crowdstrike-bug-bounty-ai-malware-research?ref=metacurity.com))

***Related:*** [*CrowdStrike*](https://www.crowdstrike.com/en-us/blog/phantomraven-llm-generated-information-stealer-for-bug-bounty-hunting/?ref=metacurity.com)

### Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED, revealing in new detail how exactly Flock Safety’s cameras track the movements of both vehicles and people.

The hackers say they are also publishing details on how they managed to obtain the software, in the hopes that other people may copy them.

The breach provides an unprecedented look inside a system that Flock has described as protected by on-device encryption. The hackers were able to copy the camera’s storage and recover an encryption key stored on the device, which unlocked videos of thousands of vehicle detections. The hackers shared the material with 404 Media and the transparency nonprofit Distributed Denial of Secrets, which shared the data with WIRED. 404 Media and WIRED then analyzed those files as part of a joint investigation.

While much of the automatic license plate reader’s most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles.

The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist’s saddlebag.

The hackers said they were able to access the Android system on the camera and found two partitions—sections of its hard drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—the videos and stills—the camera took. ([Dhruv Mehrotra and Joseph Cox / Wired](https://www.wired.com/story/hackers-flock-camera-data-shows-how-system-works/?ref=404media.co))

***Related:*** [*404 Media*](https://www.404media.co/hackers-stole-flocks-camera-software-revealing-how-the-company-tracks-cars-and-people-2/?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/image-56.png)

A screenshot from the analysis of the Flock camera. License plate redaction by 404 Media.

### The anonymous hacker group SikLik claimed to have breached the infrastructure of Russia’s Central Election Commission and its contractors ahead of the State Duma elections.

The Astra Telegram channel reported the cyberattack. According to its sources, the hackers infiltrated the systems of Rostelecom subsidiary Tsifrotekh, which is developing the State Automated System “Elections” 2.0.

The group’s members claimed they had gained access to the company’s internal documents, source code, phone call recordings, passwords, and employees’ correspondence. The archive of materials was handed over to the editorial office of Important Stories, whose journalists said they had verified its authenticity.

Russia launched the “Elections” system in early 2026\. The elections to the ninth State Duma are set to be the first federal election campaign conducted using it. ([Mezha.net](https://mezha.net/eng/news/5197b263%5Fanonymous%5Fhackers%5Fclaim/?ref=metacurity.com))

***Related:*** [*Astra*](https://t.me/astrapress/125308?ref=metacurity.com)*,* [*Caliber*](https://caliber.az/en/post/astra-hackers-claim-breach-of-russia-s-central-election-commission?ref=metacurity.com)*,* [*News.az*](https://news.az/news/hackers-claim-breach-of-russia-s-election-system?ref=metacurity.com)

### Researchers at Elastic Security report that a Brazilian banking malware operation, dubbed KREMLIN, can silently implant malicious extensions in Google Chrome and Microsoft Edge, bypassing Chromium’s built-in integrity protections to steal credentials, cookies, and active banking sessions.

Despite its name, the KREMLIN toolkit shows no apparent Russian connection. The campaign relies on Portuguese-language artifacts, lures impersonating 12 Brazilian banks, and infrastructure activity aligned with São Paulo business hours.

The attack begins with a victim manually launching a JavaScript file disguised as a banking document, invoice, or corporate file.

The loader displays a deceptive error message while quietly assessing the environment for sandboxing or virtual-machine indicators.

If the host passes those checks, it downloads additional stages, establishes scheduled-task persistence, and retrieves payload locations from an Ethereum smart contract.

One recent persistence mechanism registers a scheduled task named `MicrosoftNodeRuntimeUpdater`, configured to launch Node.js after user logon.

KREMLIN then uses a legitimate SentinelOne executable, `SentinelMemoryScanner.exe`, to sideload a malicious DLL masquerading as `SentinelAgentCore.dll`.

This DLL-side-loading approach allows the malware to execute under the cover of a trusted security-product binary.

Elastic reported disrupting more than 1,500 infections through a network canary domain, while researchers assess Brazil as the principal target. ([Mayura Kathir / GBHackers](https://gbhackers.com/kremlin-banking-malware/?ref=metacurity.com))

***Related:*** [*Elastic*](https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/kremlin-banking-malware/?ref=metacurity.com)*,* [*Tech Radar*](https://www.techradar.com/pro/security/chrome-and-edge-browsers-hijacked-by-kremlin-malware-for-credential-and-token-session-theft?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/image-57.png)

### Indian police will question Google over a lack ​of safeguards after smashing a criminal network that set up and managed more than ‌500,000 fake Gmail accounts to send hoax bomb threats to government offices.

Police in ​the western state of Gujarat broke up an email network this week that ⁠they described as sending "inter-state" bomb threats and arrested two individuals, uncovering 513,847 Gmail IDs and ​passwords being used since 2022.

Reuters is the first to report that Google itself figures in the investigation. ​The scale of fake Gmail accounts in use is unprecedented, Vivek Bheda, a senior cybercrime official of the Gujarat police, said.

"We will write to Google, ask them to make some policy changes so (safeguards) cannot be bypassed," ​Bheda said, adding that police planned to designate Google as a subject of the investigation soon formally. ([Munsif Vengattil / Reuters](https://www.reuters.com/world/indian-police-query-google-over-500000-fake-gmail-ids-linked-bomb-hoax-2026-09-15/?ref=metacurity.com))

***Related:*** [*Channel News Asia*](https://www.channelnewsasia.com/business/google-india-fake-email-ids-bomb-hoax-6385641?ref=metacurity.com)*,* [*The Hindu*](https://www.thehindu.com/sci-tech/technology/gujarat-police-to-query-google-over-500000-fake-gmail-ids-linked-to-bomb-hoax/article71467988.ece?ref=metacurity.com)*,* [*Crypto News*](https://cryptonews.net/news/security/33445982/?ref=metacurity.com)

### E-commerce giant Coupang has rejected a proposal to pay 100,000 won ($73) to each of the 50 customers who sought compensation over a massive data breach late last year, industry sources said.

“We carefully reviewed the mediation proposal but ultimately concluded that it would be difficult to accept,” Coupang notified the Korea Consumer Agency (KCA) in writing on Friday. “The decision took into account both the proactive measures we have taken so far and the potential impact of accepting the proposal at home and abroad.”

In June, Korea’s Personal Information Protection Commission fined the company 642.68 billion won and imposed an additional administrative fine of 16.8 million won over a major data breach that leaked the personal information of over 33 million users last November.

Coupang appears to have concluded that further compensation would be difficult to accept because the commerce giant has already introduced its own compensation program. The company has provided Coupang shopping vouchers worth 50,000 won each to 33.7 million people whose personal information was compromised.

Coupang's voluntary compensation package is worth about 1.69 trillion won.

Civic groups strongly criticized the company's decision.

“Coupang is essentially saying that it will fight victims in civil court over any additional liability,” a coalition of civic groups said during a press conference on Wednesday. “It is the height of shamelessness.” ([Korea JoongAng Daily](https://www.koreajoongangdaily.com/business/coupang-rejects-100000-won-payouts-for-data-breach-victims/12878726?ref=metacurity.com))

***Related:*** [*KBS World Radio*](https://world.kbs.co.kr/service/news%5Fview.htm?lang=e&Seq%5FCode=204293&ref=metacurity.com)*,* [*Seoul Economic Daily*](https://en.sedaily.com/society/2026/09/16/coupang-rejects-consumer-agency-plan-to-pay-100000-won-per?ref=metacurity.com)*,* [*SBS*](https://news.sbs.co.kr/english/article.do?news%5Fid=N1008756567&ref=metacurity.com)

### A Cybersecurity and Infrastructure Security Agency program that provides tools and capabilities to other agencies has to get speedier so it can push them toward being able to move more quickly themselves, an agency official said.

“We have to get faster,” said Richard Grabowski, acting branch chief of service delivery and deputy program manager for the Continuous Diagnostics and Mitigation program at CISA. “The way that we collaborated today wasn’t fast enough for the threats of yesterday, and they certainly aren’t going to be fast enough for the threats of tomorrow.”

That means pushing responsible automation of tasks that also can do so at scale, he said, so that experts “can focus more \[on\] dealing with the novel threats and adoption and tuning of advanced technology, and not hitting alerts every other day.”

Velocity is one of the three core goals for the CDM program, along with unification and data-driven risk management, Grabowski said at the Elastic Federal Cyber Defense Breakfast, produced by FedScoop.

Unification means keeping data out of silos so “we are connecting those deployments in a meaningful way to really stimulate reusable, actionable lessons learned,” Grabowski said. And data-driven risk management means that in the event of a crisis-level event, agencies are able to “see what is happening with timely, accurate, and trustworthy data, so that we are the tool of first response when the things hit the fan.” ([Tim Starks / CyberScoop](https://cyberscoop.com/whats-next-for-cisas-cdm-program-that-gives-cybersecurity-tools-to-federal-agencies/?mid=1&ref=metacurity.com#cid=3716433))

***Related:*** [*MeriTalk*](https://www.meritalk.com/articles/cisa-looks-to-scale-siem-as-a-service-across-federal-agencies/?ref=metacurity.com)

### US Rep. Josh Gottheimer (D-NJ), co-chair of the House AI commission, said proposals to use third-party organizations to evaluate the safety of frontier artificial intelligence models are not enough, instead endorsing a mandatory government vetting regime.

“With our cybersecurity, biosecurity, critical infrastructure, and national security on the line, every AI developer should have to submit their frontier models to the U.S. government for a short-clocked review before they release them to the public,” he said in a statement.

The use of third-party evaluators to examine the safety of AI models is a key component of a sweeping AI regulatory framework, dubbed the FRONTIER Act, championed by Reps. Jay Obernolte (R-Calif.) and Lori Trahan (D-Mass.). OpenAI has signaled its support for the provision. ([Katherine Long / Politico](https://www.politico.com/live-updates/2026/09/15/congress/gottheimer-house-ai-commission-01077569?ref=metacurity.com))

***Related***: [*Josh Gottheimer*](https://gottheimer.house.gov/posts/statement-gottheimer-says-third-party-audits-alone-dont-meet-the-moment?ref=metacurity.com)*,* [*Washington Examiner*](https://www.washingtonexaminer.com/news/house/4728420/josh-gottheimer-house-ai-third-party-review/?ref=metacurity.com)

### Best Thing of the Day: Making AI Agents Pay

Jaz-Michael King, founder of Tŵt, the Welsh and English community microblog, [recently updated](https://toot.wales/@jaz/117280619460102284?ref=metacurity.com) the site's bot policy to let AI Agents know it charges a $100 account processing fee and $10 per email.

### Worst Thing of the Day: We'll Let the World Burn Before We Consult With Cyber Pros About Hacking

Four influential experts in the cybersecurity field [said](https://www.nbcnews.com/tech/security/cybersecurity-experts-say-ai-giants-shutting-safety-plans-rcna597704?ref=metacurity.com) that their industry is worried that AI companies seem uninterested in tapping their expertise to avoid a catastrophic hacking event, or even to understand the specifics of how it might unfold.

### Closing Thought

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/image-51.png)