Threat Brief — 2026-09-19 — Ransomware gang breached, SolarWinds RCE patched
Executive summary. The most notable development today is intra-criminal conflict: ShinyHunters claims to have breached the Clop ransomware operation's Tor leak site, stealing server data and onion private keys, and is now threatening to extort the gang itself. Separately, SolarWinds patched a high-severity hard-coded key flaw in Access Rights Manager enabling unauthenticated remote code execution. Neither finding carries evidence of active exploitation at time of writing.
Top items
- SolarWinds Access Rights Manager — hard-coded key enables unauthenticated RCE. SolarWinds released updates for a high-severity flaw in ARM involving a hard-coded key that could allow unauthenticated remote code execution. No public exploit or KEV listing is indicated in the source. Organisations running ARM should treat the advisory as a priority patch candidate. (src: The Hacker News)
- ShinyHunters breaches Clop ransomware leak site, threatens extortion of the gang. ShinyHunters reportedly defaced Clop's Tor leak site, claiming theft of server data and the onion service's private keys, and is now threatening to extort Clop itself. This is a rare instance of one criminal group directly attacking another's infrastructure; it may disrupt Clop's leverage over existing victims but could also scatter stolen data into new hands. (src: BleepingComputer)
- Kaspersky reports elections where votes are cast via Telegram accounts. Researchers identified election processes where voting is tied to Telegram accounts alongside passport and SNILS (insurance number) credentials, with follow-up calls from "specialists" after fraudulent votes. This highlights the risk of using consumer messaging platforms for identity-bound civic processes. (src: SecurityLab.ru)
Themes
Adversary-on-adversary activity. The ShinyHunters–Clop incident is unusual in that a financially motivated extortion group is directly targeting another criminal operation's infrastructure. If the claims hold, the theft of onion private keys could compromise the operational security of Clop's leak-site model and potentially expose victim negotiation data.
===
