Published: 09/29/26
Tuesday opens on a patch that a lot of teams replaced with a firewall rule. Google says ShinyHunters is back on unpatched PeopleSoft servers, and the way past the WAF is one encoded letter. Also on the desk: Kiteworks asked customers to power down for a weekend, Apple fixed an iPhone bug used against specific people, and 16,000 Supabase databases are open to anyone who asks.
Lead Story
PeopleSoft attackers are walking past WAF rules. Patch HR and payroll servers now
Mandiant and GTIG report a renewed mass-exploitation wave against CVE-2026-35273, the unauthenticated PeopleTools RCE Oracle fixed on June 10. ShinyHunters now requests /%50SEMHUB/ instead of /PSEMHUB/, which slips past string-matching WAF rules. Web shells are on dozens of systems across education, healthcare, government, and more.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters: PeopleSoft holds payroll, HR, and student records, and this group runs data-theft extortion.
Also Worth Your Attention
Kiteworks told customers to power down for the weekend
After a federal threat tip, Kiteworks recommended a precautionary shutdown, then lifted it on September 27. The company says the flaw is in Advanced Forms (under 50 customers), no compromise is known, and 9.5.1 addresses all known vulnerabilities.
Why it matters: File-sharing servers are a favorite extortion target, and this vendor has lived that before.
iPhones still on iOS 26 need 26.7.1
CVE-2026-86950 is a CoreGraphics out-of-bounds write that Apple says may have been exploited against specific targeted individuals on iOS before 27. Fixed in iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.
Why it matters: The people most likely to be targeted are often the ones who deferred the big upgrade.
16,326 Supabase databases are readable by anyone
UpGuard scanned about 300,000 Supabase-backed sites and found readable tables with personal data, and sometimes passwords or tokens. The cause is missing or weak row level security, common when tables are created by code or AI agents.
Why it matters: Quick internal apps start collecting real customer data long before anyone reviews them.
Slack paste: PeopleSoft: Oracle’s June 10 fix installed (not just WAF), EMHub off if unused, grep for encoded /PSEMHUB/; Kiteworks on 9.5.1, Advanced Forms check; iOS 26 devices to 26.7.1; Supabase projects: RLS on every table.
Go Deeper
Identity & access: IAM library · Tools & playbooks: Cybersecurity Tools · Subscribe: Daily Brief
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.