Daily briefing: Friday, September 25, 2026

Bitget says suspected North Korean actors stole $351.6 million after compromising a backend wallet system and spoofing transaction data, with security systems catching the unauthorized transfers on September 24. Google Threat Intelligence and Mandiant identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), who modified the exploit to bypass WAF rules blocking the Environment Management Hub.

Elementor WordPress flaw lets attackers create admin accounts

ServiceNow security advisory (AV26-963)

Multiple vulnerabilities in ServiceNow's AI Platform, the most severe allowing unauthorized access, were disclosed by the Canadian Centre for Cyber Security and CIS MS-ISAC.

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

Bitget says suspected North Korean actors stole $351.6 million after compromising a backend wallet system and spoofing transaction data, with security systems catching the unauthorized transfers on September 24.

ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

Google Threat Intelligence and Mandiant identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), who modified the exploit to bypass WAF rules blocking the Environment Management Hub.

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

Roundcube's patched CVE-2026-48842 SQL injection is actively exploited, affecting versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.

Written by a language model from the linked articles only. Each sentence cites its sources and was checked against them, mechanically and by a model; sentences that failed either check were removed.