Daily briefing: Saturday, September 26, 2026

ShinyHunters-linked attackers exploit CVE-2026-35273 in Oracle PeopleSoft, bypassing WAF rules to deploy web shells on dozens of systems. Lunex uses BYOVD to disable kernel security callbacks before stealing browser credentials and cryptocurrency wallets.

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

ShinyHunters-linked attackers exploit CVE-2026-35273 in Oracle PeopleSoft, bypassing WAF rules to deploy web shells on dozens of systems. The ShinyHunters extortion gang uses a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw. CVE-2026-35273 has a CVSS score of 9.8 (critical) and was added to CISA's Known Exploited Vulnerabilities catalog on June 12, 2026.

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

Lunex uses BYOVD to disable kernel security callbacks before stealing browser credentials and cryptocurrency wallets.

China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks

The US and China agreed to set up a communication mechanism for artificial intelligence-related incidents.

GitHub Actions re-enabled with Mini Shai-Hulud payload still active

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code.

OpenAI's AI agents accidentally uploaded user-provided images to third-party sites

OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks.

Written by a language model from the linked articles only. Each sentence cites its sources and was checked against them, mechanically and by a model; sentences that failed either check were removed.