Jul 5 · Industry News

Hackers Lived Inside DHS’s World Cup Security Network for Weeks — Undetected

A genuinely quiet holiday cycle for fresh disclosures — no new CISA catalog additions, no notable vendor news — but the Department of Homeland Security has confirmed a breach of HSIN, its sensitive-but-unclassified information-sharing platform, that sat undetected for weeks during active FIFA World Cup security operations, with a SharePoint collaboration layer among the targeted components. Separately, ShinyHunters escalated its Council of Europe extortion claim, alleging 297 GB and roughly 429,000 files tied to the same Oracle PeopleSoft zero-day campaign already under scrutiny.

★ Top Read

DHS has confirmed a cyber incident on the Homeland Security Information Network (HSIN), its sensitive-but-unclassified hub used by federal, state, local, tribal and private-sector partners to coordinate operations and share threat information. The intrusion is believed to have occurred between late May and early June 2026 and only became public July 1; attackers targeted HSIN servers and the SharePoint system HSIN uses for document collaboration.

DHS says classified networks were not affected and the platform remains operational, but whether documents were stolen is still unclear, and no actor has been attributed. The strategic point for a federal audience: the country’s primary domestic-security coordination hub was compromised for weeks, undetected, during a live World Cup security operation — a dwell-time and visibility failure in exactly the “unclassified legacy” tier where monitoring is thinnest.

Senator Mark Warner, vice chair of the Senate Intelligence Committee, has called on DHS and the Department of Justice to investigate who got in, what they accessed, and to get partners the information they need to mitigate the exposure.

Sources: BleepingComputer, Nextgov/FCW, Sen. Warner press release, PYMNTS

Cyberattacks & Breaches

DHS confirms HSIN breach; weeks of undetected dwell time during World Cup security operations. First reported by Nextgov and confirmed by a DHS spokesperson, who stressed that classified systems were untouched and that the affected “unclassified legacy information sharing environment” was isolated. HSIN previously had a 2023 access-misconfiguration exposure, making this the platform’s second security event in three years.

So what: Both stories here are about trust in the seams — HSIN in the “unclassified, legacy, someone-else’s-problem” tier of a federal estate, and the Council of Europe via a single ERP zero-day feeding a mass campaign. Neither was caught by a control at the front door; the exposure is dwell time and cross-system visibility. The sensitivity of information-sharing infrastructure is not defined by its classification label.

ShinyHunters escalates Council of Europe extortion — 297 GB, roughly 429,000 files claimed. The extortion crew added the Council of Europe to its leak site and threatened to publish data it says spans HR, the Secretariat, the Parliamentary Assembly and the EDQM, including payroll records for more than 10,000 employees dating back to 2011, roughly 14,000 CVs, bank details and medical records. ShinyHunters attributes the intrusion to the same Oracle PeopleSoft zero-day campaign that has already hit more than 100 organizations, including the University of Nottingham. The Council of Europe says it is investigating the claims but has not confirmed a breach.

So what: Both stories here are about trust in the seams — HSIN in the “unclassified, legacy, someone-else’s-problem” tier of a federal estate, and the Council of Europe via a single ERP zero-day feeding a mass campaign. Neither was caught by a control at the front door; the exposure is dwell time and cross-system visibility. The sensitivity of information-sharing infrastructure is not defined by its classification label.

Vulnerabilities & Exposure

SharePoint RCE CVE-2026-45659. The CISA federal remediation deadline landed July 4. Federal civilian agencies were required to patch the flaw — any authenticated Site Member can trigger it — and it remains a strong prompt to verify remediation across SharePoint estates generally.

So what: A holiday weekend is precisely when hours-to-exploitation flaws with skeleton coverage bite. If the deadline was met on paper, the days after are the window to confirm it in telemetry, not the ticket queue.

Adobe ColdFusion and “Bad Epoll” remain open exposure. The CVSS 10.0 ColdFusion path-traversal flaw and the near-certain Linux/Android local-root kernel bug both remain open exposure for unpatched fleets. Fixes exist for both; the risk is patch latency, not availability. No new exploitation activity was reported over the holiday.

So what: A holiday weekend is precisely when hours-to-exploitation flaws with skeleton coverage bite. If the deadline was met on paper, the days after are the window to confirm it in telemetry, not the ticket queue.

AI Impact on Security

The week’s AI-attacker arc stands. The through-line built across the week remains the strategic story: AI-generated in-browser ransomware showed an AI surfacing a novel browser-native technique; a separate incident showed an LLM operating an intrusion end-to-end; and a modular malware framework showed AI-assisted assembly of a full kit tuned to evade the mainstream endpoint detection field. No fresh AI-attack disclosure appeared over the holiday, which makes this a moment to consolidate the argument rather than chase a new headline.

So what: The quiet day is useful — the arc is now complete enough to argue as one thesis: AI lowers the barrier to both building and running attacks, without waiting on the next incident.

Regulatory & Policy

Congressional oversight of the HSIN breach opens a federal-accountability thread. Senator Mark Warner’s demand that DHS and the Department of Justice investigate converts the incident into an oversight question: who is accountable for monitoring the unclassified legacy tier, and what visibility obligations attach to information-sharing infrastructure.

So what: The HSIN oversight angle is the more board-legible story this weekend for a federal audience — it reframes “was classified data taken?” into “why did it take weeks to see anyone was inside?”

EU AI Act obligations still take effect August 2, 2026. Unchanged: the compliance clock continues to run into a month where AI sits on both sides of the attack.

So what: The HSIN oversight angle is the more board-legible story this weekend for a federal audience — it reframes “was classified data taken?” into “why did it take weeks to see anyone was inside?”

Sources & further reading (8)

← All Industry News