ShinyHunters hijacks Clop, fake LastPass kills security tools, trusted npm release carries malware
Sep 22, 2026 · 7m
Summary
Shiny Hunters defaced Klop’s leak site with extortion threats, while a fake LastPass installer and trusted npm package delivered malware that disables security tools. Amazon blocked Meta’s Muse AI agent over privacy concerns, and Belgian sports federations are investigating a data breach affecting thousands of members. Additionally, researchers uncovered the Task Stomp backdoor, a WordPress-based malware-as-a-service operation, and a significant student data breach at the University of Munich.
Topics discussed
Shiny Hunters hijacks Klop's leak site
Fake LastPass installer delivers malware
Malware details: killing security tools
Trusted npm release carries Happler malware
Happler attack vector and registry abuse
Happler impact and mitigation advice
Belgian sports federations investigate breach
Gymnastics federation data theft details
Sponsor: Nudge Security AI agent discovery
Nudge Security features and call to action
Amazon blocks Meta's Muse AI assistant
Meta's response and AI agent consent debate
Task Stomp PowerShell backdoor discovered
Task Stomp capabilities and persistence
ClickFix copycat spreads via WordPress
Expasy malware-as-a-service details
Munich University breach exposes student data
LMU response and data status
Outro and feedback information
Listen ad-free on Castria