Defendwork ShinyHunters Escalate Oracle PeopleSoft Exploitation Amid Microsoft Mega-Patch
Article Content
- •ShinyHunters are exploiting Oracle PeopleSoft CVE-2026-35273 using WAF-bypass techniques.
- •Microsoft issued a record 974 security patches, including critical vulnerabilities.
- •Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks.
ShinyHunters, a hacking group, has escalated attacks exploiting Oracle PeopleSoft vulnerability CVE-2026-35273 following the arrest of a member in the Netherlands. This vulnerability, with a CVSS score of 9.8, is being exploited using URL-encoding techniques to bypass web application firewalls. Microsoft recently released its largest patch batch ever, addressing 974 vulnerabilities, including CVE-2026-69730 and CVE-2026-85880. Apple also patched a zero-day vulnerability in CoreGraphics, CVE-2026-86950, which may have been exploited in targeted attacks. The ongoing exploitation of Oracle PeopleSoft affects multiple sectors globally, with ShinyHunters deploying web shells to gain unauthorized access. Security experts are urging organizations to prioritize patching CVE-2026-35273 and monitor for indicators of compromise. The situation remains critical as the threat landscape evolves rapidly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Jadepuffer, ShinyHunters and Lunex Stealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AI Cyber Risks Threaten Global Financial Stability, Warns Bank of England Bank of England Governor Andrew Bailey has alerted G20 finance ministers that frontier AI models pose a significant threat to global financial stability by increasing the speed and scale of cyber attacks. This warning follows similar alerts from regulators in Hong Kong and Singapore, who noted that advanced AI could…