ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Newsletters › Past editions › ITsecurity Daily — Saturday, 26 September 2026: ShinyHunters bypasses WAF filtering to resume mass exploitation of Oracle PeopleSoft

ITSECURITY.GURU

ITsecurity Daily

Daily Briefing

ShinyHunters bypasses WAF filtering to resume mass exploitation of Oracle PeopleSoft

Good morning. The Hacker News reports that Google is warning of renewed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft, which The Hacker News states carries a CVSS score of 9.8 and can result in unauthenticated exploitation. BleepingComputer reports that the ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that were mitigating the flaw, allowing the threat actors to resume widespread exploitation of vulnerable servers. The Hacker News reports the ShinyHunters-linked activity involves deploying web shells. If you run PeopleSoft, the takeaway from both outlets is that a WAF rule alone is being bypassed, so don't rely on filtering — hunt for web shells on exposed servers.

The Record reports that Frank Balonis, CISO at Kiteworks, told Recorded Future News the company "received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers," and that Kiteworks is urging customers to stop using the platform. If Kiteworks is in your estate, that vendor instruction is the action.

On supply chain, BleepingComputer reports that two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week while still pointing to malicious code. Review any workflows that pin those Actions.

Read the full briefing →

Zoom out: The Hacker News reports Google is warning of renewed mass exploitation targeting multiple sectors globally.

Elsewhere

  • BleepingComputer: ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks Read it
  • SecurityWeek: China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks Read it
  • BleepingComputer: Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer Read it
  • BleepingComputer: Microsoft pauses KB5002907 update after Office license deactivations Read it
  • The Hacker News: Zero Trust for AI Agents Starts With Fixing Zero Visibility Read it
  • The Hacker News: Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells Read it
  • BleepingComputer: OpenAI's AI agents accidentally uploaded user-provided images to third-party sites Read it
  • SecurityWeek: OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure Read it
  • The Hacker News: SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild Read it
  • The Hacker News: Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link Read it

Sources

Every briefing is on the site, with the advisory record behind it. All briefings

You are receiving this because you subscribed at itsecurity.guru.

Headlines from other outlets belong to them; each one credits its outlet and leads to their own report.

All past editions · Get them by email