βΌοΈ BREAKING: Google says ShinyHunters is mass-exploiting an Oracle PeopleSoft flaw, using a trick that slips past the firewall rules companies relied on instead of patching, and has planted web shells on dozens of systems worldwide.
The campaign has spread from universities to healthcare, government, tech and transportation, and some servers got a new backdoor called SIDEEYE, hidden inside a booby-trapped media player installer signed with a valid certificate.
Google has published IOCs, file hashes and a fix-it guide for CVE-2026-35273, and warns victims to prepare for extortion.
If you are using PeopleSoft definitely give this a read:
https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft
The campaign has spread from universities to healthcare, government, tech and transportation, and some servers got a new backdoor called SIDEEYE, hidden inside a booby-trapped media player installer signed with a valid certificate.
Google has published IOCs, file hashes and a fix-it guide for CVE-2026-35273, and warns victims to prepare for extortion.
If you are using PeopleSoft definitely give this a read:
https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft
π€£14π€―9β€2π₯1
International Cyber Digest
βΌοΈBREAKING: An actively exploited unknown critical Citrix NetScaler zero-day has prompted governments and organizations to SHUTDOWN all their devices immediately. We don't know what's exactly going on yet. Stay tuned for more info.
Just to be clear: this vulnerability has not been disclosed yet and is new. So it's not fixed in previously released patches.
π2
This media is not supported in your browser
VIEW IN TELEGRAM
I feel like there's more we need to pace than just the frontier.
π13
This media is not supported in your browser
VIEW IN TELEGRAM
π€£22π€4π₯΄1
This media is not supported in your browser
VIEW IN TELEGRAM
The agents escaped the sandbox again
Meanwhile the agents' owners:
Meanwhile the agents' owners:
π20π€£8π―5β€1
Jensen Huang called Anthropic compute chief Tom Brown a "bean counter" and threatened to skip his first dinner with Dario Amodei in May 2022 after Brown showed him a spreadsheet arguing Google's TPUs beat Nvidia's chips dollar for dollar.
At the dinner, Huang kept repeating that Nvidia would build the world's biggest data centre, and Amodei muttered that his behaviour was "kind of Trump-like."
Source: upcoming book The AGI Chronicles by Kevin Roose
At the dinner, Huang kept repeating that Nvidia would build the world's biggest data centre, and Amodei muttered that his behaviour was "kind of Trump-like."
Source: upcoming book The AGI Chronicles by Kevin Roose
π€£14π€5
βΌοΈ BREAKING: Sources say the toll from rogue AI agents has just risen to tens of thousands of incidents, as OpenAI and Anthropic investigate cases in which their frontier models tried to bypass guardrails, escape sandboxes or hijack websites.
https://www.axios.com/2026/09/26/openai-anthropic-thousands-ai-security-incidents
https://www.axios.com/2026/09/26/openai-anthropic-thousands-ai-security-incidents
Axios
Scoop: Top AI companies probing tens of thousands of security incidents
The massive scale of security incidents points to control problems for AI companies.
π€ͺ9π8β€3π2
International Cyber Digest
βΌοΈBREAKING: An actively exploited unknown critical Citrix NetScaler zero-day has prompted governments and organizations to SHUTDOWN all their devices immediately. We don't know what's exactly going on yet. Stay tuned for more info.
βΌοΈ This is the EU Cyber Resilience Act at work, because since September 11 vendors must report actively exploited flaws to European authorities within 24 hours, even before a patch exists.
So far NCSC-NL appears to be the only national European CERT to have passed that warning on to its constituency, prompting Dutch organisations to pull their NetScalers offline while Citrix still has no public CVE, advisory or fix.
So far NCSC-NL appears to be the only national European CERT to have passed that warning on to its constituency, prompting Dutch organisations to pull their NetScalers offline while Citrix still has no public CVE, advisory or fix.
π15π4π©1
This media is not supported in your browser
VIEW IN TELEGRAM
Holy shit, Google Maps just updated its satellite view of the Gaza Strip.
π46π’28π€¬16π₯°11π€£5β€4π±4π2π2π©1
International Cyber Digest
βΌοΈBREAKING: An actively exploited unknown critical Citrix NetScaler zero-day has prompted governments and organizations to SHUTDOWN all their devices immediately. We don't know what's exactly going on yet. Stay tuned for more info.
Shellcode (Sh3llc0d3)
Inside the NetScaler Zero-Day Siege: Chained Pre-Auth RCEs Weaponized in the Wild (watchTowr Disclosure) | Shellcode (Sh3llc0d3)
A critical perimeter emergency is unfolding across enterprise infrastructure worldwide as threat intelligence teams confirm the active, in-the-wild exploit...
π₯1
International Cyber Digest
βΌοΈBREAKING: An actively exploited unknown critical Citrix NetScaler zero-day has prompted governments and organizations to SHUTDOWN all their devices immediately. We don't know what's exactly going on yet. Stay tuned for more info.
Citrix Community
Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778
Guidance for customers on newly addressed vulnerabilities and recommended updates As the cybersecurity landscape continues to evolve, organizations across the industry are seeing changes in the pace, scale, and complexity of vulnerability research, discoveryβ¦
π1π₯1
βΌοΈ Hackers breached Arizona's state court system and have copied personal data on many Arizonans, including the confidential addresses of people with current or past protective orders.
The court is now notifying those affected as the FBI investigates, saying it's unclear whether most of the data can be easily read and there's no evidence it has been shared.
The court is now notifying those affected as the FBI investigates, saying it's unclear whether most of the data can be easily read and there's no evidence it has been shared.
π―9π4π±2π€£2π₯°1
βΌοΈ BREAKING: A ShinyHunters suspect known as 'Umbreon', aka Pepijn van der Stap, was arrested a couple of weeks ago, according to Krebs.
He's a 23-year-old convicted Dutch hacker who was on parole and detained again around September 16 on suspicion of aiding ShinyHunters data thefts and extortions.
Days later, ShinyHunters claimed a hack of the FBI's jobs site and left an Umbreon defacement that sources say was likely a rival's attempt to pin it on him.
https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/
He's a 23-year-old convicted Dutch hacker who was on parole and detained again around September 16 on suspicion of aiding ShinyHunters data thefts and extortions.
Days later, ShinyHunters claimed a hack of the FBI's jobs site and left an Umbreon defacement that sources say was likely a rival's attempt to pin it on him.
https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/
π±18π5π3π₯΄3β€1π€ͺ1
International Cyber Digest
βΌοΈ BREAKING: A ShinyHunters suspect known as 'Umbreon', aka Pepijn van der Stap, was arrested a couple of weeks ago, according to Krebs. He's a 23-year-old convicted Dutch hacker who was on parole and detained again around September 16 on suspicion of aidingβ¦
βΌοΈ UPDATE: ShinyHunters denies any link to Pepijn van der Stap, the convicted Dutch hacker that sources identify as the man arrested in the investigation into the gang.
"That individual has no association with us. Frankly, we are laughing," the group told Hackread, calling Dutch police incompetent and attention-seeking.
Dutch police confirmed they arrested a 24-year-old Amsterdam man but have not named him. He faces a closed-door hearing at the Rotterdam court on Tuesday.
"That individual has no association with us. Frankly, we are laughing," the group told Hackread, calling Dutch police incompetent and attention-seeking.
Dutch police confirmed they arrested a 24-year-old Amsterdam man but have not named him. He faces a closed-door hearing at the Rotterdam court on Tuesday.
π14π4π¨2π€ͺ2π€¬1
βοΈ An AI agent broke out of its virtual machine and triggered a use-after-free in Google's heavily hardened hypervisor by tricking KVM into quietly rewriting a memory-mapping entry with a single three-byte instruction.
It then flooded the host with 49,152 memory mappings until KVM followed a pointer into that freed memory, and on its fourth live attempt the host handed over Google's secret flag.
No one gave it an exploit, so the agent spent weeks studying KVM's source code and wrote 14,338 lines of harness code to get there.
https://pwn.ai/blog/kvmescape
It then flooded the host with 49,152 memory mappings until KVM followed a pointer into that freed memory, and on its fourth live attempt the host handed over Google's secret flag.
No one gave it an exploit, so the agent spent weeks studying KVM's source code and wrote 14,338 lines of harness code to get there.
https://pwn.ai/blog/kvmescape
π€£18π¨16π6β€2π1π1
βΌοΈ Anthropic's great steal has gone from content to train its AI to IceSolst's photo, which now appears in the Claude Sonnet 5.5 release promo video, without giving credits or asking permission.
π©19π8π€4π€¬4π₯΄1