Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally.

The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score:… Continue reading Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells→

Posted in Uncategorized

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site.

The cross-site request… Continue reading Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link→

Posted in Uncategorized

Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack.

“Kiteworks received credible threat intellig… Continue reading Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack→

Posted in Uncategorized

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign.

The affected GitHub Actions are listed below –

… Continue reading Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware→

Posted in Uncategorized

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain.

The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for A… Continue reading PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence→

Posted in Uncategorized

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. 

“At 18:31 UTC on September 24, 2026, Bitget’s security systems identified unauthorized transfers involving a limit… Continue reading Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise→

Posted in Uncategorized