This day 02:06 06:06 10:06 14:07 18:08 22:08
⚠ exploit status: CVE-2026-35273 · KEV·R
Info  2026-09-26 18:08Z · last 4h · 5 findings · glm-5.2:cloud

Threat Brief — 2026-09-26 — ShinyHunters WAF evasion and lingering supply-chain payloads

Executive summary: ShinyHunters-linked actors are renewing mass exploitation of Oracle PeopleSoft (CVE-2026-35273KEV·R, already in CISA KEV) with newly reported WAF-bypass techniques for web-shell deployment. Two GitHub Actions compromised in the Mini Shai-Hulud campaign were re-enabled by their maintainer and stayed live with malicious code for over a week — a supply-chain persistence concern. New commentary underscores that AI agent deployments suffer from fundamental visibility gaps before Zero Trust controls can even be applied.

Top items

Themes

AI agent governance gap widens. The Zero Trust commentary and the Claude Opus stylistic analysis point in the same direction: as AI agents and model outputs become harder to distinguish from human activity, both access-control and content-detection tooling face diminishing effectiveness. The PeopleSoft and GitHub Actions items are unrelated in actor and vector, but both illustrate persistence in exposed infrastructure — a reminder that known-exploited flaws and compromised supply-chain components often remain accessible long after disclosure.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db