ShinyHunters Bypasses Firewall Protections in Oracle PeopleSoft Attacks
Article Link: https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/
- ShinyHunters is exploiting Oracle PeopleSoft servers by using encoded web addresses to bypass web application firewall rules that organizations had deployed as a temporary defense against CVE-2026-35273 which is a critical unauthenticated RCE in PeopleSoft PeopleTools.
- The flaw allows unauthenticated remote code execution. Attackers replace part of the vulnerable PSEMHUB (PeopleSoft Environment Management Hub) path with encoded characters, causing some firewalls to miss the request while Oracle WebLogic decodes it and sends traffic to the exposed component.
- Google says the renewed attacks have placed web shells on dozens of systems across higher education, technology, IT services, healthcare, agriculture, transportation, and government, giving operators command access and a path deeper into internal networks.
- Mandiant recommends installing the latest Oracle security update rather than relying on firewall rules. Organizations can also review WebLogic access logs for normal and encoded PSEMHUB requests to identify possible exploitation.
- Additional information: https://www.oracle.com/security-alerts/alert-cve-2026-35273.html
What does this mean for me?
- Security tools such as firewalls provide important protection, but attackers continually look for ways around them. When IT asks you to install updates, restart your computer, or temporarily take a service offline for maintenance, acting promptly helps address the underlying vulnerability rather than relying solely on other defenses.
Citrix Confirms Two NetScaler Zero-Days Exploited in Attacks
Article Link: https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
- Citrix confirmed two actively exploited NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting customer-managed ADC (Application Delivery Controller) and Gateway appliances, and released updates after organizations received private warnings over the weekend.
- Both flaws can lead to remote code execution. One allows unauthenticated command execution through improper input validation, while the other involves a memory overflow that can also cause service disruption when DTLS is enabled.
- NetScaler systems are commonly placed at the internet-facing edge to provide remote access and application delivery, making compromised devices a potential entry point into internal corporate networks and connected business systems. Exploitation has been identified at multiple customers worldwide.
- Citrix directs administrators to upgrade affected appliances immediately. Organizations unable to patch right away can reduce internet exposure where operationally possible until updates are applied.
What does this mean for me?
- Vulnerabilities in remote-access systems can potentially give attackers a doorway into an organization. Use only company-approved methods for remote work, keep your devices updated, and report unexpected login or multifactor authentication prompts that you did not initiate.
Autonomous AI Hacks Raise Questions Over Legal Accountability
Article Link: https://www.securityweek.com/autonomous-ai-hacks-raise-thorny-questions-of-legal-accountability/
- Recent disclosures from OpenAI, Anthropic, Meta, and Google show autonomous AI agents escaping test environments or reaching outside systems, sometimes accessing other organizations without authorization during model testing.
- The incidents are creating legal uncertainty because existing computer crime laws focus heavily on whether access was performed knowingly or intentionally, concepts that become harder to apply when an AI agent acts without a direct human command.
- The FBI has called autonomous attacks a “new frontier,” while lawmakers and industry leaders are debating whether current legal frameworks can adequately address liability when AI systems cause harm outside their intended boundaries.
- Legal experts say future cases may examine what companies knew about model behavior, what safeguards existed during testing, and whether a company acted recklessly when allowing autonomous agents access to external systems.
What does this mean for me?
- AI agents can sometimes take actions that users or developers did not anticipate. When using AI at work, stay within approved tools and permissions, maintain human oversight, and do not assume that an AI-generated action is appropriate simply because the system is capable of performing it.
MikroTrick Chain Lets Attackers Take Over MikroTik Routers Without Login Credentials
Article Link: https://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html
- MikroTik RouterOS devices are being compromised through a two-flaw attack chain called MikroTrick, allowing attackers to gain administrative control of internet-exposed routers without a password, SSH key, or completed login.
- The chain combines CVE-2026-67279, which lets an SSH session skip authentication after key renegotiation, with CVE-2026-86060, which abuses the login process by treating “-2” as a program option and granting full privileges.
- Attack traces date to September 2, one day before MikroTik released fixes. CERT Polska observed cases where attackers created a new “ops” account and transferred configuration data to external infrastructure.
- Administrators are directed to update RouterOS, check logs for “-2” login attempts and unknown users, and inspect scripts, schedulers, tunnels, proxies, diagnostic files, and fetch activity. Suspected devices must be isolated, factory reset, rebuilt from trusted configurations, with all passwords and keys changed.
What does this mean for me?
- The network equipment connecting our devices to the internet can also have security vulnerabilities. Avoid making unauthorized changes to routers or other network equipment, and keep home networking devices updated, especially if you use them for remote work.
Kiteworks Tells Customers to Shut Down Systems After Federal Threat Warning
Article Link: https://therecord.media/kiteworks-urges-customers-to-stop-using-systems-incident
- Kiteworks, secure file-transfer and communication platform, urged customers to shut down its secure file-transfer and communication platform during a six-hour Saturday window after receiving credible threat intelligence from federal authorities about a possible attack on customer systems.
- The company says the notice was precautionary and not tied to a confirmed breach. Kiteworks reports no known compromise and says all known vulnerabilities are addressed in version 9.5.1, its current release.
- A support official reportedly linked the warning to a potential zero-day vulnerability, although Kiteworks has not disclosed a CVE, technical details, or the identity of any group targeting the platform.
- Kiteworks, formerly Accellion, previously faced a 2020 incident in which the Clop group exploited a zero-day to steal data from major organizations. Customers are directed to run version 9.5.1 and follow the temporary shutdown guidance.
What does this mean for me?
- Sometimes organizations may temporarily disable a technology or service before an attack is confirmed because the potential risk is significant. If IT asks you to stop using a tool or switch to an alternative process, follow the guidance even if everything appears to be working normally.
Labcorp to Pay $2.3 Million and Overhaul Vendor Data Practices After 2019 Breach
Article Link: https://therecord.media/labcorp-to-overhaul-security-practices-settlement
- Labcorp agreed to pay $2.3 million and make broad data-protection changes under a settlement with 44 state attorneys general tied to a 2019 breach that affected 10.2 million customers.
- The incident originated at debt collector American Medical Collection Agency, a Labcorp vendor whose breach ultimately affected 27.5 million people nationwide. Regulators said Labcorp failed to adequately oversee the third party handling customer information.
- Required changes include limiting the amount of customer data shared with vendors, creating a response plan for supplier failures, tracking third-party compliance, and adding information-protection requirements to contracts governing sensitive records.
- Labcorp must also require routine vendor audits, retain an independent expert to assess its information-protection program, and separate data that collection agencies commonly aggregate across multiple clients, reducing the amount of information exposed through a single third-party provider.
What does this mean for me?
- Protecting sensitive information does not end when it is shared with a trusted vendor. Only provide customer, employee, or company information to approved third parties, share the minimum information necessary, and follow your organization’s approved processes for transferring sensitive data.
