Threat Brief — 2026-09-26 — ShinyHunters WAF evasion and lingering supply-chain payloads
Executive summary: ShinyHunters-linked actors are renewing mass exploitation of Oracle PeopleSoft (CVE-2026-35273KEV·R, already in CISA KEV) with newly reported WAF-bypass techniques for web-shell deployment. Two GitHub Actions compromised in the Mini Shai-Hulud campaign were re-enabled by their maintainer and stayed live with malicious code for over a week — a supply-chain persistence concern. New commentary underscores that AI agent deployments suffer from fundamental visibility gaps before Zero Trust controls can even be applied.
Top items
- Oracle PeopleSoft CVE-2026-35273KEV·R — ShinyHunters WAF-bypass exploitation continues. Google is warning of renewed mass exploitation of this known PeopleSoft vulnerability, with attackers now bypassing web application firewalls to reach the vulnerable endpoints and deploy web shells. The flaw is listed in CISA's Known Exploited Vulnerabilities catalogue and has been associated with ransomware operations. This is a developing story first reported 2026-09-26 by Mandiant; the new detail is the WAF evasion technique and Google's independent warning. (src: The Hacker News)
- Compromised GitHub Actions re-enabled with Mini Shai-Hulud payload still active. Two third-party GitHub Actions previously compromised in the Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week while still pointing to malicious code. Any CI/CD pipeline consuming these actions during that window may have pulled the payload. First reported 2026-09-16 by The Hacker News; the development is that the maintainer's re-enablement left the malicious references live for an extended period. (src: BleepingComputer)
- Commentary: Zero Trust for AI agents hampered by zero visibility. A new analysis argues that organisations deploying AI agents lack basic observability into agent behaviour, data flows, and decision paths — making Zero Trust enforcement a secondary concern behind simply seeing what agents do. The piece is commentary rather than a disclosed vulnerability, but it frames a growing operational gap as agent adoption accelerates. (src: The Hacker News)
- Claude Opus 5.5 writing patterns shifting. Analysis of Anthropic's Claude Opus 5.5 shows fewer em dashes, shorter sentences, and simpler wording compared with its predecessor — reducing obvious AI-generated text markers. This is not a security vulnerability, but it has detection implications: content-moderation and AI-text-classification tools that rely on stylistic hallmarks may lose effectiveness as model output converges toward human prose norms. (src: BleepingComputer)
Themes
AI agent governance gap widens. The Zero Trust commentary and the Claude Opus stylistic analysis point in the same direction: as AI agents and model outputs become harder to distinguish from human activity, both access-control and content-detection tooling face diminishing effectiveness. The PeopleSoft and GitHub Actions items are unrelated in actor and vector, but both illustrate persistence in exposed infrastructure — a reminder that known-exploited flaws and compromised supply-chain components often remain accessible long after disclosure.
