Skip to main content
GBU_week41_2026.jpg
The Good, the Bad and the Ugly

The Good, the Bad and the Ugly in Cybersecurity - Week 41 (2026)

By SentinelOne

The Good | Federal Authorities Disrupt Cybercrime Syndicates & Courts Sentence Dark Web Co-Founder

Jordanian authorities detained Saif al-Din Khader, a suspected member of the ShinyHunters extortion group. Following his arrest, sources report that Khader (aka Rey) has been cooperating with the FBI and international agencies to identify and locate the remaining co-conspirators, leveraging his digital devices and communication logs. 

The reported detention follows an ongoing federal investigation on ShinyHunters’ self-claimed breach of the FBI’s administrative systems.

A federal court indicted Zohar Pinhasi for allegedly defrauding cybercrime victims that had hired his ransomware remediation company, MonsterCloud. MonsterCloud advertised the use of proprietary technology to restore encrypted files without paying ransoms. However, court filings allege Pinhasi routinely paid ransomware operators directly for decryption keys before billing clients inflated fees. 

Prosecutors claim that the scheme facilitated over $8 million in secret ransom payments while generating $19 million in revenue over five years. If convicted, Pinhasi stands to face up to 20 years in prison for one count of conspiracy to commit wire fraud and two counts of wire fraud.

A U.S. District Judge sentenced Raheim Hamilton to 40 years in prison for co-creating and operating Empire Market, one of the largest dark web marketplaces prior to its shutdown. Operating online as “Sydney” and “ZeroAngel”, Hamilton facilitated over four million transactions valued at $430 million between 2018 and 2020. 

Empire Market evaded detection by only accepting cryptocurrency payments while employing tumblers and mixers to obscure all transaction trails. Drug sales accounted for nearly $375 million of total volume, alongside stolen credentials, personally identifiable information (PII), and hacking tools. On top of the jail time, Hamilton has also agreed to forfeit three properties, 1,230 Bitcoin, and 24.4 Ether and must pay a $5 million fine. 

The Bad | Human Phishers Impersonate AI Ad Portals to Intercept Credentials and MFA Codes 

Researchers uncovered a human-operated phishing platform impersonating advertising management portals for popular AI chatbots, including ChatGPT, Gemini, Claude, Perplexity, Meta Muse, and Manus. While each brand had tailored lures, the main goal was to get victims to enter their credentials and multi-factor authentication (MFA) codes using spoofed login windows.

The operators offered up specialized “campaign optimization” capabilities such as spend audits, campaign planning, and business-account connections to target advertising agency staff, media buyers, and account administrators. Promoted through fake invitation emails, the campaign leveraged realistic landing pages such as museads[.]ai to entice unsuspecting users into connecting their enterprise accounts.

Clean webpage screenshot with OpenAI header links, Log in/Sign up buttons, headline and weekly Google Ads brief details plus bullets and CTA Subscribe to my brief
Spoofed ChatGPT “Monday Brief” page (Source: Island)

When a victim initiates the connection workflow, the platform executes a Browser-in-the-Browser (BitB) attack by rendering a fake browser window complete with a spoofed address bar pointing to trusted origins like accounts.google.com or Okta tenants. Behind the spoofed interface, the platform logs password attempts and transmits device fingerprints to attacker servers using Socket.IO connections. 

Then, a human operator actively monitors victim interactions in real time, issuing commands via Socket.IO events to steer users through specific MFA challenges, including SMS codes, authenticator app prompts, push approvals, and number-matching screens.

Built on a Next.js and Socket.IO technology stack, the underlying platform shares infrastructure across payment refund and corporate recruitment phishing schemes. One backend domain appeared in 73 archived scans across 25 page domains between late May and late June, serving AI ad lures, refund pages, and a fake careers site alike. Hundreds of victim submissions were also observed over the course of tracking the campaign, with activity ongoing at publication.

By hijacking legitimate manager accounts with clean spending histories, threat actors run unauthorized advertising campaigns or sell access on Telegram. Account recovery often takes weeks or months while compromised accounts continue serving malicious ads, extending financial damage across agency client bases. 

The Ugly | Threat Actors Target Atlassian Data Center Flaw Within Hours of Public POC

Threat actors are actively exploiting a critical (CVSS: 9.3) arbitrary file access vulnerability affecting Atlassian Data Center products within just two hours of a public proof-of-concept (PoC) being published. Tracked as CVE-2026-21589, the flaw impacts multiple enterprise applications, including Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. 

The vulnerability allows unauthenticated attackers to retrieve specific files within the web application root directory through a single, tailored HTTP request. This stems from Atlassian's web-resource path resolution logic, which improperly converts custom path traversal sequences into relative directory paths. 

By combining these traversal sequences with specific plugin endpoints, unauthenticated attackers can bypass path restrictions and access restricted application files. While the vulnerability does not allow directory enumeration and requires prior knowledge of exact file names and paths, sensitive configuration files are still exposed. 

In systems like Atlassian Crowd and Jira, attackers could target configuration files storing administrative credentials, allowing them to gain unauthorized privilege elevation, create rogue administrative accounts, and modify user permissions.

Telemetry gathered so far points to initial exploitation attempts against honeypot networks originating from several IP addresses, with a Nuclei template now released. Most initial scanning activity focused on fingerprinting exposed instances and sweeping for common configuration files containing embedded secrets. 

CVE-2026-21589_previdian.jpg
First-party evidence of exploit activity (Source: Previdian)

To mitigate risk, Atlassian released security updates across all affected product lines and advised organizations to apply temporary mitigations, including Web Application Firewall rules, Tomcat request blocking, and restricting internet exposure. Automated scanning templates mean exploitation will keep pace with disclosure, leaving unpatched instances exposed for as long as they stay online. 

Related Articles

Decorative background gradient

Subscribe

Get the Latest From the SentinelOne Blog