ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Briefings › ShinyHunters bypasses WAF filtering to resume mass exploitation of Oracle PeopleSoft
IT SECURITY DESK

ShinyHunters bypasses WAF filtering to resume mass exploitation of Oracle PeopleSoft

The day's reporting centres on active, unauthenticated exploitation of a critical PeopleSoft flaw and Kiteworks urging its customers to stop using the platform after a warning from federal intelligence authorities.

The Hacker News reports that Google is warning of renewed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft, which The Hacker News states carries a CVSS score of 9.8 and can result in unauthenticated exploitation. BleepingComputer reports that the ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that were mitigating the flaw, allowing the threat actors to resume widespread exploitation of vulnerable servers. The Hacker News reports the ShinyHunters-linked activity involves deploying web shells. If you run PeopleSoft, the takeaway from both outlets is that a WAF rule alone is being bypassed, so don't rely on filtering — hunt for web shells on exposed servers.

The Record reports that Frank Balonis, CISO at Kiteworks, told Recorded Future News the company "received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers," and that Kiteworks is urging customers to stop using the platform. If Kiteworks is in your estate, that vendor instruction is the action.

On supply chain, BleepingComputer reports that two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week while still pointing to malicious code. Review any workflows that pin those Actions.

BleepingComputer reports Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users reported it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations.

On malware and abuse, The Hacker News reports that Ontinue described a four-stage attack chain distributing Psychedelic Stealer via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks, part of a malware-as-a-service platform called Lunex; the same reporting says Lunex Stealer abuses an AMD driver to disable security monitoring and steal browser credentials. SecurityWeek reports a new Windows botnet, x47.c, weaponises xAI Grok to choose from predefined actions and maintain persistence. BleepingComputer reports OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks.

In enforcement and policy, Krebs on Security reports a U.S. Army soldier who pleaded guilty to hacking multiple telecommunications companies and stealing call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison and ordered to pay nearly $300,000 in restitution. SecurityWeek reports the US and China agreed to set up a communication mechanism for AI-related incidents. The Register reports on a voice-phishing ad impersonating a "Google Security Team" — a reminder to socialise current vishing lures with staff.

Related