Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ShinyHunters says it does not plan to publish FBI-related data it claims to have stolen, but that is the group’s stated intention—not a guarantee or independent verification. Separately, a Defense Manpower Data Center breach reportedly affected millions of people. An OBS Studio exploit chain could turn unsafe viewer-submitted HTML in a Browser Source into code execution, but it depended on an unsafe overlay or attacker-controlled browser content.

How do the three security stories differ?

Incident What is reported Key qualification
ShinyHunters and FBI-related data The group told 404 Media it had decided not to publish data it claims to have taken. The statement is the group’s own; the available reporting does not verify the claimed cache or guarantee what the group will do.
Defense Manpower Data Center (DMDC) A Defense Department official told CNN that 2.76 million living people and 294,000 deceased people were affected. The counts are attributed to the official through CNN, not to an independently published forensic report.
OBS Studio Browser Source A researcher demonstrated a chain from unsafe rendering of viewer-controlled HTML to arbitrary code execution. The remote entry point required unsafe handling of attacker-controlled content; the report does not establish that every default OBS installation was remotely exploitable by any viewer.

Will ShinyHunters release the FBI data?

404 Media reported on September 28, 2026, that ShinyHunters told the outlet it had decided from the beginning not to publish the FBI-related data it claims to have obtained. The group said: “Since the very beginning we had made our decision that we would never publish this data. We have never intended to nor have we ever planned to.” That is a statement of intent from the group, as quoted by 404 Media—not confirmation that it possesses the described material, that the material is complete, or that it will keep its promise.

The reported cache allegedly includes personal information about FBI employees and applicants, such as addresses, job roles, spouses’ names and medical records. Those details remain claims about the breach and the data. 404 Media noted counterintelligence and personal-safety concerns: criminals in the same ecosystem have previously used hacked phone data to track and harass FBI agents.

Hackaday’s October 2, 2026, roundup also recounts that ShinyHunters objected to an FBI press release and characterized the incident as “This was all a marketing campaign to protect our business and actively combat disinformation”. That is the group’s framing, not an independently established account of the FBI’s actions or the incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How many people were affected by the Pentagon data breach?

The Pentagon story concerns the Defense Manpower Data Center, a separate incident from the FBI-related claims. CNN, in reporting republished by KVIA, said a Defense Department official reported that the breach affected 2.76 million living people and 294,000 deceased people. The affected population can include current or former personnel and dependents. CNN’s report says the Pentagon confirmed these figures after the initial publication.

Hackaday describes DMDC as handling records for 60 million current and former service members. That is the center’s records population, not the reported number of people affected by this breach; it should not be used as a breach count.

What happened, and when?

According to CNN’s reporting on a breach notification letter, unauthorized users began accessing files on a vulnerable DMDC server in October 2025. The issue was found and remediated in July 2026—an interval of about nine months from the reported start of access to discovery and remediation.

What information was involved?

The reported files included Social Security numbers and other personal information. An “occupational specialty” field appeared in some cases. The available reporting does not identify who accessed the server, so attributing the incident to a particular criminal group or foreign government would go beyond what is established.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is OBS vulnerable to malicious chat messages?

It can be, under specific conditions. In a September 22, 2026, technical disclosure, Orange Cyberdefense Switzerland researcher Dylan Iffrig-Bourfa described a chain involving OBS Studio 32.2.2 on updated Windows 11. The demonstrated remote entry point was a Twitch chat overlay that inserted viewer messages as raw HTML without sanitization. A malicious message could then execute script inside an OBS Browser Source.

The researcher’s chain also relied on the embedded Chromium browser running with its sandbox disabled and on a V8 component affected by CVE-2024-7971. Orange reported that the embedded engine was Chromium 127.0.6533.120 with V8 12.7.224.18; the V8 issue affected Chromium versions before 128.0.6613.84. The researcher described the chain as reaching arbitrary code execution on the streamer’s machine.

This is not evidence that any viewer can automatically compromise a fresh, unmodified OBS installation simply by posting in chat. The unsafe overlay was essential to the demonstrated remote route. An attacker-controlled page loaded into a Browser Source or browser dock is also relevant to the browser-exploitation stage.

How should streamers and overlay authors reduce the risk?

  • Render viewer messages as text. Do not insert chat messages or other viewer-controlled content as raw HTML.
  • Sanitize HTML if it is genuinely required. Iffrig-Bourfa’s guidance is: “If a chat message is text, render it as text. If you genuinely need HTML, sanitize it properly.”
  • Treat Browser Sources as untrusted-content surfaces. The disclosure warns: “Anything inside a Browser Source should be treated as untrusted input and, in particular, no widget should ever render viewer content as HTML.”
  • Update OBS and check current release information. The disclosure recorded browser and sandbox fixes in progress, with related pull requests merged on September 10 and 17, 2026. Those dates do not establish the status of fixes in every later release, so consult current OBS release notes rather than relying on the disclosure’s snapshot.

Microsoft had documented exploitation of CVE-2024-7971 in the wild, and CISA added it to its Known Exploited Vulnerabilities catalog, according to the Orange disclosure. That history makes it especially important not to treat unsafe browser content or an outdated embedded engine as harmless.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What else was in Hackaday’s security roundup?

The October 2 roundup also covered attacks involving operating-system file-notification systems, a DIVD compromise involving Zammad, and active exploitation of Cisco Catalyst SD-WAN Manager and Citrix NetScaler vulnerabilities. Separately, Cisco’s September 30, 2026, advisory for CVE-2026-76504 described an API authentication bypass through which unauthenticated remote attackers could gain administrator privileges, reported active exploitation, and recommended upgrading to a fixed release. These are additional items in the roundup, not part of the three incidents above.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.