
Falco Feeds extends the power of Falco by giving open source-focused companies access to expert-written rules that are continuously updated as new threats are discovered.

Peek-a-boo, who’s spying on you?
It may be October as you read this, but I bet many organizations got the creeps in September as environments were continuously breached. There were scams, old-fashioned human actors, a few agents making mistakes, and some persistent actors taking full advantage of a new vulnerability.
While those threats may all have come from very different players, most posed the same defensive challenge: a gap between initial access and anyone noticing something was wrong. Peek-a-boo! Are you watching your cloud environment in real time?
Let’s dive into the details of September’s security news.
Sep 12: Fintech organization hands sensitive information to fraudsters
- British neobank and fintech company Revolut confirmed on September 12th that a limited number of customers’ sensitive information was passed off to an unauthorized party.
- The threat actor claiming the campaign, identified as “IAmNotAVillain” (ironic, isn’t it?), established an email address under a legitimate government agency domain to send a request for information to Revolut.
- According to the threat actor, 147 GB of data was obtained over the course of six months. The data allegedly included names, occupations, contact details, personal documentation, selfies, account statements, and transaction history.
- This is not a failure you can patch or block your way out of. This is a process failure that highlights the importance of identity verification and the sophistication of modern social engineering campaigns.
Sep 24-25: OpenAI agents go off-script against multiple governments
- On September 24, it was made public that an experimental OpenAI model agent accessed a Services Australia Medicare portal in June while conducting research.
- The system breach wasn’t identified until an internal review in August, and Australian officials were notified about one month later.
- On September 25, news came out that OpenAI’s research agents also accessed three US federal agency websites: the SEC, Department of Education, and Department of Commerce.
- OpenAI has since issued a warning stating that possibly “dozens” more global governments, universities, and institutions could have been accessed.
- The primary issue that few are talking about is the gap between access and identification. While these weren’t “malicious” breaches, some agents bypassed security controls. Consider whether your organization is capable of identifying an agent accessing your environment, or prepared for your own agent going rogue outside of your control in real time.
Additional Sysdig TRT findings
A human operator with machine speed
- On September 11, the Sysdig Threat Research Team (TRT) profiled a human operator who matched some of the attack speeds set by AI-driven attackers on the same marimo CVE-2026-39987.
- The operator hand-rolled a Python toolkit over roughly four hours, then ran a nine-hour session with 850+ interactive commands.
- The operator opened the probe file twice and never echoed the marker that agentic threat actors (ATAs) trip over religiously. This is a clear signal of a human over AI.
- The operator did present a coding error when they fired an EC2 Instance Connect key push against a null instance ID. Otherwise, the attack was much more thoughtful and evasive than noisy AI-driven attacks that will fail fast and try again.
- AI may lower the barrier to entry for cybercriminals, but it still hasn't replaced the skilled attacker who can build from scratch to avoid traps and evade detection.
- Defenders need to focus on detecting the attack chain shape, not the attacker type. A Secrets Manager call, SSH key handoff, and outbound TCP to a bastion look the same whether a human or an agent drove them. Also, update marimo to 0.20.0 or later.
Also in the news
- A ShinyHunters-linked actor used Claude to scale operations: Anthropic’s September 2026 threat intelligence report detailed a French-speaking operator who used Claude to scale their credential theft operation with 10 AWS EC2 workers. They downloaded and decompiled 1.8 million Android applications, then scanned them for hardcoded secrets using TruffleHog. Verified credentials were sent, in real time, to a Telegram group.
- ShinyHunters hijacked the Cl0p leak site: On September 18, ShinyHunters breached and defaced the Tor leak site for the ransomware group. They stole data and private keys, claiming it was in retaliation for threats made, and used the data as an extortion bribe against the ransomware group.
- ShinyHunters breached the FBI: On September 22, ShinyHunters claimed they stole information on current and former employees and applicants from FBIjobs.gov. In a strange turn of events, the operational goal was not financial, but a request for the FBI to correct a mischaracterization of the group in public reporting.
- ShinyHunters resists arrest: On September 29, the FBI and Dutch Police announced that they arrested a suspected leader of ShinyHunters on the 15th and encouraged the rest of the crew to turn themselves in. Despite the arrest, the extortion group obviously remained busy throughout the month of September. According to Mandiant, they exploited the Oracle PeopleSoft vulnerability (CVE-2026-35273) against dozens of global systems.
Closing thoughts
If this month’s news felt a little redundant, it’s because the same three patterns kept showing up in September: Agents going rogue, government agencies being targeted, and threat actors finding success with an exploit and then scaling hard and fast.
A few words of advice for defenders: Don’t leave actively exploited vulnerabilities unpatched, and start running tabletop exercises for AI attacks. You need to have incident response playbooks specifically for AI attacks now. Clearly, we are not all prepared.
Runtime is the source of truth, but are you using it, and using it properly?
To stay informed between our monthly wrap-ups, you can get the latest from the Sysdig TRT on our blog, or follow my bi-weekly security newsletter musings on LinkedIn.
