Security news.
Active exploitation and emergency advisories dominate today's updates, led by renewed attacks bypassing web application firewalls to compromise Oracle PeopleSoft deployments. In response to imminent attack intelligence, enterprise vendor Kiteworks has taken the extraordinary measure of urging customers to take systems offline, while CISA warns of active targeting against Microsoft SharePoint and MikroTik hardware. Organizations should prioritize updating perimeter appliances and auditing exposed enterprise software.
ShinyHunters Bypasses WAF Rules to Exploit Oracle PeopleSoft Flaw
Attackers are leveraging URL-encoding tricks to circumvent web application firewalls and resume widespread exploitation of the critical CVE-2026-35273 remote code execution vulnerability.
Kiteworks Advises Customers to Shut Down Servers Over Attack Threats
Secure file-sharing vendor Kiteworks warned enterprise clients to temporarily power down their servers following credible federal threat intelligence regarding an imminent cyberattack.
CISA Adds Microsoft SharePoint and MikroTik RouterOS Bugs to KEV Catalog
CISA confirmed active in-the-wild exploitation of SharePoint code injection flaw CVE-2026-65660 and MikroTik RouterOS vulnerability CVE-2026-67279, mandating swift federal remediation.
Bitget Suffers $351.6 Million Theft in Suspected North Korean Cyber Heist
Cryptocurrency exchange Bitget reported unauthorized transfers compromising hot and warm wallets, with security researchers attributing the massive intrusion to North Korean state-sponsored actors.
High-Severity Elementor Plugin Flaw Enables Rogue WordPress Admin Creation
A cross-site request forgery vulnerability rated CVSS 8.8 in the popular Elementor Website Builder allows unauthenticated attackers to take over WordPress sites if an administrator clicks a malicious link.
Compromised GitHub Actions Re-Enabled While Still Housing Malware
Two third-party GitHub Actions originally breached during the Mini Shai-Hulud campaign were mistakenly re-enabled by a maintainer, leaving malicious code accessible for over a week.
Lunex Stealer Leverages AMD Driver to Neutralize Security Monitoring
The Ukrainian-targeted Psychedelic Stealer operation was revealed as part of the Lunex MaaS platform, abusing legitimate AMD drivers to bypass endpoint defenses and harvest browser credentials.
Salesforce Patches Zero-Click 'SalesBleed' Flaws in Agentforce
Three vulnerabilities discovered in Salesforce Agentforce could allow attackers to hijack trusted AI agents to exfiltrate enterprise data and execute cross-platform phishing.