# Archive
Browse past daily curated stories
Sunday, September 27, 2026
-
1The Hacker News generalAttackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Google is tracking mass exploitation of CVE-2026-35273 (CVSS 9.8), a critical unauthenticated RCE vulnerability in Oracle PeopleSoft, linked to ShinyHunters. The campaign targets multiple sectors globally and involves web shell deployment. Security teams running PeopleSoft should treat this as an active incident-response priority given the critical severity and widespread targeting.
-
2BleepingComputer generalShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
ShinyHunters is bypassing WAF mitigations for Oracle PeopleSoft CVE-2026-35273 using a URL-encoding trick, effectively re-enabling mass exploitation against servers that were considered protected. This is significant for defenders who applied WAF rules as a temporary mitigation rather than patching, as those controls are now rendered ineffective.
-
3The Hacker News generalSharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
CISA added two actively exploited flaws to its KEV catalog: CVE-2026-65660 (CVSS 8.8), a code injection vulnerability in Microsoft SharePoint, and a separate MikroTik RouterOS flaw. Federal agencies face mandatory remediation deadlines under KEV, and both products have broad enterprise and ISP deployment making rapid patching critical.
-
4The Hacker News generalKiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
Kiteworks (formerly Accellion) urged customers to take their systems offline for nine hours over a weekend after receiving credible threat intelligence from federal authorities about an imminent attack against Kiteworks infrastructure. Given Accellion's history as a high-value target in prior mass-exploitation campaigns, any Kiteworks deployment should be treated as actively threatened pending further disclosure.
-
5The Hacker News generalBitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
Suspected North Korean threat actors stole $351.6 million from Bitget's hot and warm wallets via a backend compromise detected at 18:31 UTC on September 24, 2026. Cold wallets were reported unaffected, and Bitget's $464 million User Protection Fund is being used to cover losses — making this one of the largest crypto heists attributed to DPRK actors.
-
6CyberScoop generalArmy soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies
Cameron Wagenius, a US Army soldier on active duty, was sentenced for his role in high-profile 2024 breaches targeting AT&T, Snowflake, and other major companies. The case underscores insider-threat risks within cleared personnel and the operational security failures that allowed a service member to conduct a sustained cybercrime spree against critical infrastructure.
-
7BleepingComputer generalCISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
CISA is warning of active exploitation of CVE-2026-5430, a critical authentication bypass in WSO2 enterprise products, alongside separately exploited flaws in Microsoft SharePoint and Adobe Commerce. WSO2 is widely used as an API gateway and identity provider, meaning exploitation could enable lateral movement into enterprise identity infrastructure.
-
8The Hacker News generalLunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
Ontinue researchers uncovered Lunex, a malware-as-a-service platform distributing the Psychedelic Stealer via ClickFix-style fake Cloudflare CAPTCHA pages on compromised Ukrainian websites. The four-stage attack chain abuses an AMD driver to disable security monitoring and targets browser credentials, making it notable for its BYOVD (Bring Your Own Vulnerable Driver) component against Ukrainian-speaking users.
-
9The Hacker News generalElementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
A high-severity CSRF vulnerability (CVSS 8.8) in the Elementor Website Builder WordPress plugin — which has tens of millions of installs — allows unauthenticated attackers to create rogue administrator accounts if an existing admin clicks a crafted link. No CVE has been assigned yet, and admins should verify plugin versions and apply available patches immediately.
-
10SecurityWeek generalRoundcube Webmail Vulnerability in Attackers’ Crosshairs
CVE-2026-48842, an unauthenticated SQL injection vulnerability in Roundcube Webmail, is being actively exploited in the wild. Roundcube is widely deployed by governments and organizations globally and has been a repeated target of nation-state actors including APT28, making prompt patching essential for any exposed instance.