Actively exploited Citrix ADC flaws top the day; ShinyHunters run a new Oracle PeopleSoft campaign as the FBI's job sites stay offline
CISA lists two Citrix ADC vulnerabilities and one WordPress flaw as known to be exploited, while Mandiant ties a live ShinyHunters campaign to an Oracle PeopleSoft bug.
Patch Citrix ADC first. CISA's Known Exploited Vulnerabilities catalog lists CVE-2026-88771 (CVSS 9.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and CVE-2026-88772 (CVSS 8.1) as known to be exploited. Citrix's advisory lists Citrix ADC 13.1 as affected up to the fix in 13.1-64.23. The same advisory (CTX697096) covers CVE-2026-88775, CVE-2026-88776 and CVE-2026-88777 — each CVSS 9.8 and not on the KEV catalog — with the same affected range and fix. Move to 13.1-64.23 per Citrix's advisory and apply any interim mitigation it names; CISA directs affected asset owners to follow BOD 26-04 patching guidance or discontinue the product where mitigations are unavailable.
ShinyHunters is exploiting a bug in Oracle PeopleSoft. The Record reported that Mandiant warns the group is using workarounds for the flaw in a new campaign. Help Net Security reported the FBI's applicant portals at apply.fbijobs.gov and fbijobs.gov/special-agents remain offline following what it describes as successful compromises by ShinyHunters via a PeopleSoft zero-day. If you run PeopleSoft, treat it as exposed and hunt for compromise. On the enforcement side, Krebs on Security reported Dutch authorities arrested a 23-year-old convicted cybercriminal on suspicion of aiding ShinyHunters, and that remaining members escalated their attacks in the days after; BleepingComputer reported Dutch police confirmed a 24-year-old Amsterdam man was arrested this month in the same investigation.
WordPress users should update. CISA's catalog lists CVE-2026-87902 (CVSS 8.1) as known to be exploited; the WordPress advisory lists versions from earliest up to the fix in 4.7.37 as affected. Move to 4.7.37.
Microsoft flagged two threats. The Register reported Microsoft warns that JadePuffer hijacked Azure identities and used them to destroy cloud resources, characterising it as agentic ransomware. The Hacker News reported Microsoft's technical analysis of NeedyMantis, a malware family used to maintain long-term access after a breach, seen in a small number of targeted intrusions at telecommunications organisations, universities, medical nonprofits and intergovernmental organisations.
Apple released updates for an out-of-bounds write in CoreGraphics affecting older versions of iOS, iPadOS and macOS; The Hacker News reported Apple said it "may have been exploited in targeted attacks." Update older Apple devices.
Also reported Monday: The Hacker News reported Bitget said an attacker exploited a flaw in a third-party security product to obtain high-level internal credentials and steal about $388 million. BleepingComputer reported researchers found more than 16,000 misconfigured Supabase databases exposing tables with personally identifiable information, passwords or authentication tokens — audit your Supabase access rules. BleepingComputer also reported Keio Corporation confirmed a ransomware attack disrupted business systems, and that Times Car confirmed a breach affecting approximately 6.6 million user accounts.
Sources
- BleepingComputer — Japan's Keio confirms ransomware attack disrupted business systems
- The Register — JadePuffer crims hijacked Azure identities and used them to blow up cloud resources
- The Record — ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
- The Hacker News — Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
- SecurityWeek — Call for Presentations Open for 2026 CISO Forum Virtual Summit
- Krebs on Security — Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
- Help Net Security — FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day
- Schneier on Security — New Attack Against RSA
- BleepingComputer — Times Car confirms data breach affecting 6.6 million user accounts
- BleepingComputer — Dutch police confirm arrest in ShinyHunters hacking investigation
- BleepingComputer — Misconfigured Supabase apps expose data in over 16,000 databases
- The Hacker News — Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
- The Hacker News — IAM for AI agents: A Practical Enterprise Framework
- The Hacker News — Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M