Tuesday’s brief: PeopleSoft attackers slip past WAFs, then Kiteworks, iPhones, and leaky Supabase apps

By George Bailey   Published: 09/29/26   2 min read

Published: 09/29/26

Tuesday opens on a patch that a lot of teams replaced with a firewall rule. Google says ShinyHunters is back on unpatched PeopleSoft servers, and the way past the WAF is one encoded letter. Also on the desk: Kiteworks asked customers to power down for a weekend, Apple fixed an iPhone bug used against specific people, and 16,000 Supabase databases are open to anyone who asks.

Lead Story

PeopleSoft attackers are walking past WAF rules. Patch HR and payroll servers now

Mandiant and GTIG report a renewed mass-exploitation wave against CVE-2026-35273, the unauthenticated PeopleTools RCE Oracle fixed on June 10. ShinyHunters now requests /%50SEMHUB/ instead of /PSEMHUB/, which slips past string-matching WAF rules. Web shells are on dozens of systems across education, healthcare, government, and more.

Why it matters: PeopleSoft holds payroll, HR, and student records, and this group runs data-theft extortion.

See the fix order →

Also Worth Your Attention

Kiteworks told customers to power down for the weekend

After a federal threat tip, Kiteworks recommended a precautionary shutdown, then lifted it on September 27. The company says the flaw is in Advanced Forms (under 50 customers), no compromise is known, and 9.5.1 addresses all known vulnerabilities.

Why it matters: File-sharing servers are a favorite extortion target, and this vendor has lived that before.

Check if you’re exposed →

iPhones still on iOS 26 need 26.7.1

CVE-2026-86950 is a CoreGraphics out-of-bounds write that Apple says may have been exploited against specific targeted individuals on iOS before 27. Fixed in iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.

Why it matters: The people most likely to be targeted are often the ones who deferred the big upgrade.

See which devices need it →

16,326 Supabase databases are readable by anyone

UpGuard scanned about 300,000 Supabase-backed sites and found readable tables with personal data, and sometimes passwords or tokens. The cause is missing or weak row level security, common when tables are created by code or AI agents.

Why it matters: Quick internal apps start collecting real customer data long before anyone reviews them.

Run the five-minute check →

Slack paste: PeopleSoft: Oracle’s June 10 fix installed (not just WAF), EMHub off if unused, grep for encoded /PSEMHUB/; Kiteworks on 9.5.1, Advanced Forms check; iOS 26 devices to 26.7.1; Supabase projects: RLS on every table.

Go Deeper

Identity & access: IAM library · Tools & playbooks: Cybersecurity Tools · Subscribe: Daily Brief

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.