Skip to content
New SharePoint exploit, Australian OpenAI hack developments, Kiteworks urges stoppage

New SharePoint exploit, Australian OpenAI hack developments, Kiteworks urges stoppage

Linkedin • September 28, 2026

This vulnerability, (CVE-2026-65660) was fixed by Microsoft with its August 2026 Patch Tuesday updates. It is described as a “code injection issue that lets an authenticated attacker with low-level access to an affected server execute arbitrary code without user interaction. There is now reliable evidence of observed attacks against it, the company said. Cybersecurity and Infrastructure Security Agency has added this to its KEV catalog – the 16th SharePoint vulnerability in there – and for this one federal agencies have a patching deadline of today, September 28.

Details and doubts emerge regarding OpenAI hack of Australian Health portal

This is a follow-up to a story we covered on Friday, regarding claims that an OpenAI AI agent hacked an Australian government Medicare statistics portal in June. Australian officials including the Prime Minister, Anthony Albanese, said the agent bypassed access controls and reached non-public files, although no personal Medicare information was accessed. Since then, researchers reviewing archived website code now question whether the agent actually “hacked” anything, given that the site’s own code reportedly directed visitors to an unauthenticated endpoint, meaning the agent may simply have followed instructions embedded in the website. Neither OpenAI nor the Australian government has released the agent’s activity logs, leaving the exact sequence of events unresolved.

Kiteworks urges customers to stop using platform

Kiteworks has urged customers to temporarily shut down its file-transfer and secure-communications platform after receiving “credible threat intelligence” from U.S. federal authorities a possible attack. The company recommended a six-hour shutdown window while it and law-enforcement partners investigate. Kiteworks says it has no evidence that its systems have been compromised and describes the warning as precautionary. A company support representative reportedly referred to a possible zero-day vulnerability, but no CVE or technical details have been disclosed. Kiteworks was previously known as Accellion and operated a file transfer tool until December 2020 when the Clop group used a zero-day vulnerability to steal data from dozens of high-profile companies including the University of Colorado, the Washington State Auditor Office, Flagstar Bank, airplane maker Bombardier, and U.S. retail store chain Kroger.

Microsoft pauses update after Office license deactivations

This pause applies to the rollout of the KB5002907 Microsoft 365 update. Some users have reported that the update deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations. The optional update was released to help users update Microsoft 365 Apps installations that are more than 90 days out of date. According to one expert, although the update is listed as optional, it had installed automatically on some of his customers’ devices.

Big thanks to our sponsor, Intezer

Rydox admin faces a 20 year stretch

This follows a guilty plea last week from Ardit Kutleshi, a 28 year old citizen of Kosovo, in regard to the creation and administration of the Rydox cybercrime marketplace. Rydox has been active since February 2016. Its sales of stolen PII, access devices, and cybercrime tools, affected thousands of victims in the U.S. The U.S. authorities seized the Rydox domain in late 2024, working in conjunction with Royal Malaysian Police in Kuala Lumpur. Kutleshi’s brother, Jetmir, who also helped operate the marketplace pleaded guilty separately and was sentenced in December 2025.

Two unpatched Citrix NetScaler RCE Zero-Days under active exploitation

According to security firm watchTowr speaking on Saturday, these vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild. This flaw is not the authentication bypass flaw (CVE-2026-19490) , that we reported on last week. Citrix has not confirmed this this current zero-day, nor have they published a fix. “Some administrators say they have taken appliances offline rather than wait for one to be available.”

ShinyHunters upgrade their Oracle PeopleSoft attacks with WAF bypass

Following up on a story we covered in June, the ShinyHunters extortion gang is “using a URL-encoding trick to bypass web application firewall rules that mitigated an Oracle PeopleSoft (CVE-2026-35273) flaw.” This has allowed them to resume widespread exploitation of a flaw on vulnerable servers. This follows on from a June 10 report from BleepingComputer regarding the ShinyHunters exploitation of an Oracle PeopleSoft zero-day. Oracle fixed the vulnerability the day, but in a new report, Google ’s Mandiant (part of Google Cloud) says ShinyHunters has now modified its exploit to bypass the WAF rules. A link to a more detailed description of the technique is available in the show notes to this episode.

Welsh police force suffers cyberattack

Police in south western Wales said on Friday a cyberattack “affecting the force disrupted some non-emergency systems and may have compromised staff information.” The incident earlier this month, and no evidence has been found to show that information belonging to members of the public was affected. The police force “did not say how the breach occurred or what staff data may have been involved. No group had yet claimed responsibility.”

Spotify , Apple Podcasts , YouTube , RSS link , Amazon Music , add as an Alexa Skill , or "Cybersecurity Headlines" on your favorite podcast app.

Cybersecurity Headlines

To view or add a , sign in

More articles by CISO Series

Extracted Entities

APT Groups (2)

Attack Types (1)

Countries (2)

Industries (1)