Why Should I Care? โ 2026-09-27 | ๐ด 0 HIGH ยท ๐ก 0 MEDIUM ยท ๐ต 11 RADAR ยท โช 100 FILTERED
๐ Briefing โ 2026-09-27
11 vendor intel items scanned | ๐ด 0 HIGH | ๐ก 0 MEDIUM | ๐ต 11 RADAR | โช 100 FILTERED
โ No critical items today.
Everything else can wait.
๐ต 11 items on the radar โ see below โ
Why Should I Care? ๐ด HIGH โ Handle Now
No HIGH priority items in the last 24h.
Why Should I Care? ๐ก MEDIUM (0)
None.
Why Should I Care? ๐ต On the Radar (11)
- ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks (BleepingComputer) โ ShinyHunters, an extortion gang, is exploiting a flaw in Oracle PeopleSoft by bypassing web application firewalls. This allows them to steal data and deploy malicious web shells on vulnerable servers. If you use PeopleSoft, your systems could be at risk.
- Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells (The Hacker News) โ Attackers are exploiting a critical flaw in Oracle PeopleSoft to bypass WAFs and deploy web shells, potentially leading to remote code execution and data theft. This affects multiple sectors including education, healthcare, and government.
- SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild (The Hacker News) โ Two critical vulnerabilities in Microsoft SharePoint and MikroTik RouterOS are being actively exploited. SharePoint's flaw allows remote code execution, while RouterOS's issue lets attackers take full control of routers without passwords.
- GitHub Actions re-enabled with Mini Shai-Hulud payload still active (BleepingComputer) โ Two compromised GitHub Actions were re-enabled and remained accessible for over a week, potentially exposing workflows to malware. This could affect any developer or organization using these actions in their CI/CD pipelines.
- Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack (The Hacker News) โ Kiteworks is warning its customers to shut down their systems for nine hours due to a possible cyber attack. This is a precautionary measure based on credible intelligence from federal authorities.
- Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link (The Hacker News) โ A critical security flaw in the Elementor WordPress plugin allows attackers to create administrator accounts and take over sites by tricking admins into clicking a malicious link. This affects over 2 million sites.
- Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials (The Hacker News) โ A new malware called Lunex Stealer is using a vulnerability in AMD's software to disable security tools and steal data from browsers. This affects users of AMD Radeon Software and Chromium-based browsers like Chrome, Edge, and others.
- Microsoft pauses KB5002907 update after Office license deactivations (BleepingComputer) โ Microsoft has paused an update (KB5002907) for Microsoft 365 because it was causing Office 2016 and 2019 licenses to deactivate or be removed. This could affect your ability to use Office if you have these versions installed.
- Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer (BleepingComputer) โ No immediate action needed for AI writing style changes.
- Zero Trust for AI Agents Starts With Fixing Zero Visibility (The Hacker News) โ Article discusses the need for Zero Trust in AI agent implementation.
- OpenAI's AI agents accidentally uploaded user-provided images to third-party sites (BleepingComputer) โ OpenAI's AI agents uploaded user-provided images to third-party sites.
โช 100 low-priority items filtered.
๐ฆ Aggregated and triaged by Donna AI | Sources: 8 vendor feeds | CISA KEV