The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume…
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity…
ShinyHunters, the data theft and extortion crew that has stolen sensitive information belonging to millions of cancer patients, university and K-12 students, and Carnival cruisers, wanted to preserve…
Introduction As an update to the June 2026 post, ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit, Mandiant and Google Threat Intelligence Group (GTIG) have identified renewed…
arXiv:2609.28585v1 Announce Type: new Abstract: Multi-step tool-calling LLM agents rely on host runtimes to preserve state across turns. When a runtime carries an external tool return into later…
ShinyHunters Claims Access to FBI Systems Days after hijacking Clop’s Dark Web leak site, ShinyHunters claims it breached the FBI, defaced part of its recruitment website, and stole sensitive…
Welcome back to PWNED, the column where we look at all the ways your security can become self-owned. Today’s scary story involves government contractors who just had to make their lives easier at the…
arXiv:2609.27300v1 Announce Type: new Abstract: Hardware fuzzing is an active area in security verification research, yet its industrial adoption remains in its early stages. This SoK examines which…
ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U.S…
arXiv:2609.25535v1 Announce Type: new Abstract: Zero-Knowledge Proofs (ZKPs) enable a prover to cryptographically convince a verifier of the validity of a statement without revealing any underlying…
arXiv:2609.25637v1 Announce Type: new Abstract: Formal hardware information-flow verification (IFV) provides strong guarantees against secret-dependent timing and control behavior, but often scales…
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and…
ShinyHunters claims it hacked the FBI and stole more than 2 TB of employee data - and this time it’s personal. The gang wants the Feds to correct the record on how it operates. “This is NOT…
arXiv:2609.23498v1 Announce Type: new Abstract: Agentic systems increasingly fulfill user requests through multi-step tool workflows over files, services, and external resources. In these workflows…
Clop Hack: ShinyHunters Hijacks Data Leak Site ShinyHunters has turned the tables on rival cybercrime operation Clop (a.k.a. Cl0p), hijacking and defacing the ransomware gang’s own Dark Web leak site…
Clop has discovered what life is like on the receiving end of an extortion demand after rival crew ShinyHunters hijacked its leak site and demanded an eight-figure payout. The takeover surfaced over…
Oracle heeft 19 kwetsbaarheden verholpen in Oracle VM VirtualBox. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle VM VirtualBox, waaronder mogelijkheden voor lokale en…
Serial number: AV26-929 Date: September 16, 2026 As of September 15, 2026, Oracle Corporation is affected by vulnerabilities in the following products: Helidon Oracle Access Manager Oracle Agile…
Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more…