ShinyHunters exploit CVE-2026-35273 in Oracle PeopleSoft using URL encoding to bypass WAF rules, deploy web shells and spread ...
Google have observed ShinyHunters launching a renewed mass-exploitation campaign against vulnerable Oracle PeopleSoft servers.
Attackers hijacked Ukrainian websites to deliver a fake Cloudflare CAPTCHA that installs Psychedelic Stealer and steals ...
Windows 10 has had far fewer bugs than Windows 11 in 2026. We compared nine months of updates for both, and the pattern is ...
Attackers use fake delivery and refund complaints to trick employees into downloading ZIP files containing PureRAT and ...
FortiGuard found SectopRAT hidden in modified audio software files, using staged loading to steal browser data and remotely ...
The latest version of the MacSync info-stealing malware for macOS can hide its malicious commands inside a public iCloud ...
TWEAKOS combines credential theft with an account storefront inside one Telegram bot. According to an analysis of two exposed ...
This follow-up report details how UNC6240 (ShinyHunters) is mass-exploiting Oracle PeopleSoft (CVE-2026-35273) by bypassing WAF rules via a single URL-encoded character, providing full analysis of the ...
My desktop documents suddenly won't open” or “There's a cloud icon on my file.” These are common consultations I've received ...
Microsoft has fixed a known issue that breaks the built-in File History backup feature on some Windows systems after installing the September 2026 security updates.
Discover how AvisLoader uses Tox peer-to-peer messaging for C2, ClickFix delivery, shortcut persistence, and payload ...