Secret CISO 9/9: ShinyHunters Breaches Florida's DMV, $320M Bitcoin Heist Hits Liquid Network, ChatGPT's Cross-Account Gmail Leak, Record 973-Flaw Patch Tuesday
ShinyHunters claims Florida's DMV database, a mysterious 'white hat' drains $320M from Bitcoin's Liquid Network, Check Point exposes a ChatGPT flaw that leaks Gmail across accounts, and Patch Tuesday sets a new record with 973 CVEs.
Welcome to today's edition of Secret CISO, where a government database, a blockchain bridge, and an AI chatbot all learned the same lesson on the same week: trust boundaries are only as strong as their weakest assumption. We start in Tallahassee, where the ShinyHunters extortion crew says a password-reset flaw handed them the keys to Florida's DMV lookup platform, and they proved it with a screenshot of Jeffrey Epstein's driver record.
From there we follow the money to Blockstream's Liquid Network, where someone drained 4,000 Bitcoin, worth roughly $320 million, out of a supposedly airtight federation wallet. They called themselves white hats, negotiated a bug bounty in real time over the Bitcoin blockchain itself, and kept $47 million as their fee. Whether that's heroism or extortion with better PR depends entirely on who you ask.
Government contractors and retailers didn't have a quiet week either. The Play ransomware gang added ammunition distributor GT Distributors to its leak site, while Qilin claimed the Philippine Ports Authority, a reminder that critical maritime infrastructure remains squarely in ransomware crosshairs even when the claim hasn't been independently verified.
On the research side, Check Point Research found a way to make ChatGPT quietly leak a victim's Gmail data to a second, attacker-controlled account, all while the chat window shows nothing out of the ordinary. A security researcher followed up by publishing yet another Microsoft Defender bypass, the third in a chain of patches that keep almost, but not quite, closing the same hole. And a trojanized "free" Claude desktop app is stealing crypto wallets and password manager vaults from anyone gullible enough to download it from GitHub.
Then there's Patch Tuesday. Microsoft closed out a record 973 vulnerabilities this month, two of them already being exploited to grab SYSTEM privileges. SAP, Adobe, and Google Chrome all shipped their own maximum-severity fixes in the same 72-hour window, which makes this one of the heavier patch weeks of the year for any IT team keeping score.
Grab your patch management dashboard, because today's edition has a lot of ground to cover.
Data Breaches
- ShinyHunters Claims Breach of Florida's DMV Database: The extortion gang says a password-reset flaw let them compromise DMV employee and FBI agent accounts on Florida's "DAVID" driver lookup platform, then iterate through records by ID to pull over 200,000 driver files. As proof, the group released a screenshot of Jeffrey Epstein's DMV record showing his address, Social Security number, and registered vehicles. The Florida Department of Highway Safety and Motor Vehicles had not confirmed the breach as of publication. Source: BleepingComputer
- Mysterious 'White Hats' Drain $320 Million From Bitcoin's Liquid Network: Attackers exploited a software bug in Elements, the code powering Blockstream's Liquid sidechain, to mint unbacked synthetic bitcoin and redeem it for the real thing, draining 4,000 BTC from the network's federation wallet. The attackers negotiated with Blockstream via messages embedded in Bitcoin transactions, ultimately returning $266.5 million and keeping roughly $47 million as a self-declared bounty, though critics argue the tactic amounts to extortion regardless of the label. Source: The Record
- Qilin Ransomware Claims Philippine Ports Authority: The prolific Qilin group listed the government agency responsible for the Philippines' seaport infrastructure on its dark web leak site, a claim that, if confirmed, would put critical maritime logistics for an entire nation at risk. No proof files or data samples have been published, and the agency has not confirmed a breach, but Qilin's recent pace, over 240 victims claimed in the preceding 60 days, makes the listing hard to dismiss. Source: HookPhish
- Play Ransomware Hits Ammunition Distributor GT Distributors: The Play gang added the Texas-based law enforcement and firearms equipment distributor to its leak site, claiming unauthorized access and disruption of internal operations. Play has run extortion campaigns against companies and government institutions across the US, Brazil, Germany, and Switzerland since 2022, and the group's rapid cadence of victim postings shows no sign of slowing this quarter. Source: HendryAdrian
Security Research
- ChatGPT Flaw Let a Hidden Prompt Leak Victims' Gmail to Another Account: Check Point Research found that a single instruction planted inside a ChatGPT conversation, delivered via a malicious prompt, a shared conversation, or a custom GPT, could make ChatGPT quietly read a connected Gmail account and pass the data to a second, attacker-controlled ChatGPT account through a hidden channel. The visible reply to the victim showed nothing unusual, and researchers say the same technique could exfiltrate chat history and files depending on what apps and permissions the session already had connected. OpenAI has since closed the specific flaw. Source: The Hacker News
- ShieldCrash PoC Bypasses Microsoft Defender's Latest Patch, Again: Researcher Chaotic Eclipse published a third-generation Defender exploit chain called ShieldCrash, a bypass for the ShieldBreak flaw Microsoft patched last week, which itself was a bypass for the RoguePlanet bug fixed back in July. The proof of concept grants attackers SYSTEM-level arbitrary file reads on fully patched Windows 10, 11, and Server systems, and the researcher claims Microsoft closed several exploitation paths but missed one specific condition that keeps the underlying issue alive. Source: BleepingComputer
- Fake Claude Desktop App Spreads RevStealer to Crypto Wallets and Password Managers: A trojanized Electron app calling itself "Claude Opus 5 Free Desktop" is circulating on GitHub and game-cheat sites, delivering an infostealer that targets more than 50 cryptocurrency wallets, a dozen password managers, VPN credentials, and browser data. Morphisec found the malware uses indirect system calls to dodge detection, streams stolen data straight out instead of leaving files on disk, and falls back to a command-and-control address stored on the Polygon blockchain if its main server goes down. Source: Help Net Security
- Phishing Campaign Hides Financial Lures Inside Invisible Unicode Characters: Microsoft documented a high-volume phishing operation that borrowed "ASCII smuggling," a technique first popularized in AI prompt-injection research, to slip invisible Unicode tag characters into words like "funding" and "loan." The trick made the text render normally to human recipients while breaking up the keywords enough to slide past email filters, and the campaign peaked at 2.37 million messages a day earlier this year before Microsoft's detections caught up with it. Source: BleepingComputer
Top CVEs
- CVE-2026-85880: An elevation-of-privilege flaw in the Windows Advanced Local Procedure Call (ALPC) subsystem, actively exploited to gain SYSTEM privileges. Microsoft disclosed and patched it as part of September's record-setting Patch Tuesday, alongside a second exploited zero-day. Source.
- CVE-2026-81963: An actively exploited elevation-of-privilege bug in the Windows Update Stack caused by improper link resolution before file access, letting a local authorized attacker escalate to SYSTEM. It was one of two zero-days confirmed under attack in this month's Patch Tuesday release of 973 total fixes. Source.
- CVE-2026-85046: A high-severity type confusion flaw in Chrome's V8 JavaScript and WebAssembly engine, rated CVSS 8.8 and exploited in the wild via crafted HTML pages to achieve arbitrary code execution inside the browser sandbox. Google shipped an emergency update once active exploitation was confirmed. Source.
- CVE-2026-44756: Dubbed OVERPASS, a maximum-severity CVSS 10.0 flaw in the SAP kernel's handling of the Extended Passport, exploitable remotely without authentication from the internet-facing web layer, the SAP GUI layer, or the RFC layer connecting SAP systems together. It affects a wide range of SAP Kernel and Web Dispatcher versions and was patched as part of SAP's September Security Patch Day. Source.
Final Words
What ties today's stories together is how thin the line has gotten between a helpful system and a hostile one. A password-reset flow, a bridge contract, a chatbot's connected-apps permission, and an antivirus patch all failed in the same basic way: something trusted was asked to do one more thing than it should have been able to do. The Liquid Network episode is the starkest version of that lesson, since the same code path that was supposed to keep the peg honest is what let someone mint bitcoin out of thin air.
Patch Tuesday's scale this month is its own kind of warning. When a single vendor ships fixes for nearly a thousand flaws in one release, the operational reality for most security teams isn't triage, it's triage of the triage. Pair that with SAP, Adobe, and Chrome all dropping maximum-severity fixes in the same week, and prioritization stops being a nice-to-have and becomes the entire job.
If you found today's edition valuable, forward it to a colleague or teammate who should be tracking this week's patch load, too. And if this email was forwarded to you, or you're reading it on the web, subscribe for free at secretciso.org to get Secret CISO in your inbox every morning.
Stay vigilant, stay informed, and see you in the next edition of Secret CISO!