ITsecurity Daily
Daily Briefing
ShinyHunters bypasses WAF filtering to resume mass exploitation of Oracle PeopleSoft
Good morning. The Hacker News reports that Google is warning of renewed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft, which The Hacker News states carries a CVSS score of 9.8 and can result in unauthenticated exploitation. BleepingComputer reports that the ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that were mitigating the flaw, allowing the threat actors to resume widespread exploitation of vulnerable servers. The Hacker News reports the ShinyHunters-linked activity involves deploying web shells. If you run PeopleSoft, the takeaway from both outlets is that a WAF rule alone is being bypassed, so don't rely on filtering — hunt for web shells on exposed servers.
The Record reports that Frank Balonis, CISO at Kiteworks, told Recorded Future News the company "received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers," and that Kiteworks is urging customers to stop using the platform. If Kiteworks is in your estate, that vendor instruction is the action.
On supply chain, BleepingComputer reports that two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week while still pointing to malicious code. Review any workflows that pin those Actions.
Zoom out: The Hacker News reports Google is warning of renewed mass exploitation targeting multiple sectors globally.
Elsewhere
- BleepingComputer: ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks Read it
- SecurityWeek: China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks Read it
- BleepingComputer: Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer Read it
- BleepingComputer: Microsoft pauses KB5002907 update after Office license deactivations Read it
- The Hacker News: Zero Trust for AI Agents Starts With Fixing Zero Visibility Read it
- The Hacker News: Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells Read it
- BleepingComputer: OpenAI's AI agents accidentally uploaded user-provided images to third-party sites Read it
- SecurityWeek: OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure Read it
- The Hacker News: SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild Read it
- The Hacker News: Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link Read it
Sources
- ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks BleepingComputer
- Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials The Hacker News
- China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks SecurityWeek
- U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions Krebs on Security
- Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee Schneier on Security
- Kiteworks urges customers to stop using platform after warning from federal intelligence agencies The Record
- Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script The Register
- Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer BleepingComputer
- Microsoft pauses KB5002907 update after Office license deactivations BleepingComputer
- GitHub Actions re-enabled with Mini Shai-Hulud payload still active BleepingComputer
- OpenAI's AI agents accidentally uploaded user-provided images to third-party sites BleepingComputer
- New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining SecurityWeek
- Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells The Hacker News
- Zero Trust for AI Agents Starts With Fixing Zero Visibility The Hacker News
Share this issue
Facebook · X · Reddit · LinkedIn · WhatsApp · Email · Bluesky
Every briefing is on the site, with the advisory record behind it. All briefings