← Latest brief

Security news.

·Afternoon Brief

Active exploitation and emergency advisories dominate today's updates, led by renewed attacks bypassing web application firewalls to compromise Oracle PeopleSoft deployments. In response to imminent attack intelligence, enterprise vendor Kiteworks has taken the extraordinary measure of urging customers to take systems offline, while CISA warns of active targeting against Microsoft SharePoint and MikroTik hardware. Organizations should prioritize updating perimeter appliances and auditing exposed enterprise software.

BLEEPINGEXPLOIT
6h agoREAD

ShinyHunters Bypasses WAF Rules to Exploit Oracle PeopleSoft Flaw

Attackers are leveraging URL-encoding tricks to circumvent web application firewalls and resume widespread exploitation of the critical CVE-2026-35273 remote code execution vulnerability.

THN
17h agoREAD

Kiteworks Advises Customers to Shut Down Servers Over Attack Threats

Secure file-sharing vendor Kiteworks warned enterprise clients to temporarily power down their servers following credible federal threat intelligence regarding an imminent cyberattack.

THNKEV
16h agoREAD

CISA Adds Microsoft SharePoint and MikroTik RouterOS Bugs to KEV Catalog

CISA confirmed active in-the-wild exploitation of SharePoint code injection flaw CVE-2026-65660 and MikroTik RouterOS vulnerability CVE-2026-67279, mandating swift federal remediation.

THNNATION-STATE
1d agoREAD

Bitget Suffers $351.6 Million Theft in Suspected North Korean Cyber Heist

Cryptocurrency exchange Bitget reported unauthorized transfers compromising hot and warm wallets, with security researchers attributing the massive intrusion to North Korean state-sponsored actors.

THNVULN
15h agoREAD

High-Severity Elementor Plugin Flaw Enables Rogue WordPress Admin Creation

A cross-site request forgery vulnerability rated CVSS 8.8 in the popular Elementor Website Builder allows unauthenticated attackers to take over WordPress sites if an administrator clicks a malicious link.

BLEEPINGBREACH
11h agoREAD

Compromised GitHub Actions Re-Enabled While Still Housing Malware

Two third-party GitHub Actions originally breached during the Mini Shai-Hulud campaign were mistakenly re-enabled by a maintainer, leaving malicious code accessible for over a week.

THNBREACH
7h agoREAD

Lunex Stealer Leverages AMD Driver to Neutralize Security Monitoring

The Ukrainian-targeted Psychedelic Stealer operation was revealed as part of the Lunex MaaS platform, abusing legitimate AMD drivers to bypass endpoint defenses and harvest browser credentials.

SECURITYWEEKPATCH
1d agoREAD

Salesforce Patches Zero-Click 'SalesBleed' Flaws in Agentforce

Three vulnerabilities discovered in Salesforce Agentforce could allow attackers to hijack trusted AI agents to exfiltrate enterprise data and execute cross-platform phishing.

Generated twice daily from public security RSS feeds. Informational only.