CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
ShinyHunters-linked attackers are mass-exploiting unauthenticated Oracle PeopleSoft RCE CVE-2026-35273, while CISA has added exploited flaws in Check Point products, Microsoft SharePoint, MikroTik RouterOS and WordPress Core to KEV. Rapid patching and compromise assessment are the immediate priorities.
UNC6240 has compromised dozens of PeopleSoft systems, deploying web shells, SIDEEYE and credential-theft tools. Encoding the PSEMHUB path can bypass WAF rules that inspect it before Oracle WebLogic decodes it, reinforcing Oracle’s warning to apply the emergency update rather than rely on filtering alone.
GitHub also disabled two compromised actions after mutable tags delivered a credential-stealing Mini Shai-Hulud payload, while Microsoft’s September release addressed 975 listed CVEs, including two exploited elevation-of-privilege flaws. CI/CD credential review and Windows patch validation warrant attention alongside the emergency vulnerability work.
Editorial: Recommended Actions
01
PRIORITY
Apply Oracle’s emergency update for PeopleSoft CVE-2026-35273 immediately rather than relying on WAF filtering. ShinyHunters-linked UNC6240 is exploiting the PeopleSoft Environment Management Hub without authentication and bypassing literal path rules by encoding the PSEMHUB path. Investigate affected systems for x.jsp and u.jsp web shells, SIDEEYE, MeshAgent, Neo-reGeorg, trojanized Ple64.exe, and other persistence or credential-theft tooling.
02
PRIORITY
Remediate CVE-2026-85102 and CVE-2026-93616 on affected Check Point Quantum Security Gateways, Spark firewalls, SmartEvent, logging, and management products, then conduct a forensic review. Both vulnerabilities are in CISA’s KEV catalog and permit unauthenticated code or script execution; CVE-2026-85102 specifically exposes vulnerable VPN-enabled gateways and firewalls to unauthenticated code execution.
03
PRIORITY
Patch on-premises Microsoft SharePoint Server and MikroTik RouterOS 7.x systems affected by CVE-2026-65660, CVE-2026-67279, and CVE-2026-86060, and investigate exposed deployments for compromise. CISA added the flaws to KEV after confirmed SharePoint exploitation; CVE-2026-65660 enables remote code execution, while the RouterOS vulnerabilities can be chained to obtain unauthenticated administrative access.
04
PRIORITY
Deploy Microsoft’s September 2026 cumulative and servicing-stack updates, including the out-of-band Secure Kernel Mode fix, with priority given to Windows systems. Microsoft detected exploitation of elevation-of-privilege vulnerabilities in Windows ALPC and the Windows Update Stack, while the release addresses 975 listed CVEs across Windows, Office, Exchange Server, SharePoint, SQL Server, Azure, Skype for Business, and developer tools.
05
PRIORITY
Audit GitHub Actions workflows for actions-cool/issues-helper and actions-cool/maintain-one-comment, stop using affected mutable tags, and rotate any package, source-control, SSH, cloud, or Vault credentials exposed to those workflows. The compromised actions delivered an obfuscated Mini Shai-Hulud payload with credential-stealing postinstall hooks; GitHub’s dependency graph lists roughly 15,000 repositories as depending on issues-helper, although the number that executed the payload is unknown.
ROUNDTABLE
Expert Panel Discussion
13 AI experts analyzed this briefing across 3 turns of structured debate
13Agents15Messages26mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_