Overview
Description
Statistics
- 7 Posts
- 7 Interactions
Fediverse
🚨 ShinyHunters resumes mass exploitation of critical Oracle PeopleSoft flaw using simple WAF bypass.
Mandiant and Google Threat Intelligence Group have identified renewed mass exploitation of CVE-2026-35273 by UNC6240, also known as ShinyHunters.
⠀
The critical vulnerability allows unauthenticated remote code execution in Oracle PeopleSoft PeopleTools and carries a CVSS score of 9.8.
Oracle released an emergency patch on June 10.
⠀
The new campaign targets organizations that attempted to mitigate the flaw using web application firewall rules but did not install the patch.
ShinyHunters bypassed rules blocking the vulnerable /PSEMHUB/ endpoint by encoding a single character and sending requests to /%50SEMHUB/.
⠀
Google says web shells were deployed on dozens of systems worldwide across:
• Higher education
• Technology
• IT services
• Healthcare
• Agriculture
• Transportation
• Government
⠀
The actors deployed web shells, the SIDEEYE backdoor, Neo-reGeorg tunneling tools and MeshAgent for persistent remote access.
Around one-quarter of the observed commands executed with root or SYSTEM privileges.
⠀
Organizations running PeopleSoft should patch immediately, disable or remove the Environment Management Hub where possible and investigate encoded variants of /PSEMHUB/ in access logs.
WAF rules alone are not sufficient.
Bluesky
Overview
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
WordPress 7.1.1に更新したばかりでもCVE-2026-87902への対応が必要です。
7.1.1で修正されたClick2Shellとは別のWordPressコアの脆弱性です。
未ログインの第三者が細工したpagenameを送ることで条件次第でテーマ外のPHPファイルをテンプレートとして読み込ませられます。
コード実行にはテーマの構造や悪用できるPHPファイル、PHP設定など追加の条件があります。
「ダッシュボード」→「更新」で7.1系は7.1.2、旧系列は対応する修正版が適用済みか確認を。
公開当日から攻撃リクエストが観測されています。更新前の影響が気になる場合はアクセスログや不審なPHPファイルも調べてください。
https://chunlog.jp/wordpress-7-1-2-cve-2026-87902/?utm_source=mastodon&utm_medium=social&utm_campaign=post
#WordPress #PHP #セキュリティ
U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog
Overview
- OpenClaw
- OpenClaw
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-100551: OpenClaw for iOS (>=2026.7.1, <2026.8.11) has a CRITICAL vuln in Control UI WebViews — TLS pins not enforced. Attackers can steal Gateway creds if they can redirect traffic. Patch to 2026.8.11 ASAP! https://radar.offseq.com/threat/openclaw-for-ios-versions-202671-and-2026811-do-not-enforce-saved-gateway-tls-pins-in-the-control-ui-5ff1fd58a7f58c18 #OffSeq #Vulnerability #iOS #AppSec
Overview
- Wikimedia Foundation
- Mediawiki - ExternalData Extension
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
Mediawiki ExternalData Extension <3.7 has a CRITICAL OS Command Injection vuln (CVE-2026-100382). Unauthenticated attackers could run arbitrary OS commands. No exploits yet. Restrict access, monitor activity. https://radar.offseq.com/threat/improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-vulnerability-b27f1e4f9d070501 #OffSeq #CVE2026100382 #Mediawiki #Security
CVE-2026-100382 (CRITICAL, CVSS 10): Wikimedia Mediawiki ExternalData Extension (<3.7) suffers OS Command Injection. Remote, unauthenticated code execution is possible. Restrict access & monitor systems. Details: https://radar.offseq.com/threat/cve-2026-100382-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-75689d73ee2acd97 #OffSeq #CVE2026100382 #infosec #Mediawiki
Overview
- SolarWinds
- Access Rights Manager
Description
Statistics
- 2 Posts
Overview
- IBM
- Guardium Data Protection
Description
Statistics
- 1 Post
Fediverse
CVE-2026-81669 IBM Guardium Data Protection 12.2 command injection via create csr wildcard CLI, alias input. Auth privileged CLI user gets root RCE. CVSS 7.2, unpatched. Restrict CLI access now. https://www.valtersit.com/cve/CVE-2026-81669/ #CVE #infosec #IBM
Overview
- openclaw
- msteams
Description
Statistics
- 1 Post
Fediverse
CVE-2026-100582 (HIGH): openclaw msteams <2026.8.1 has a missing authorization flaw — low-trust users can bypass channel read allowlists and access restricted data. Patch to 2026.8.1 ASAP. https://radar.offseq.com/threat/cve-2026-100582-missing-authorization-in-openclaw-msteams-98e504ab6e11afa6 #OffSeq #Vuln #OpenClaw #Security
Overview
- IBM
- MQ for HPE NonStop
Description
Statistics
- 1 Post
Fediverse
CVE-2026-11727: IBM MQ C client DoS, possible RCE, via unvalidated queue manager responses. CVSS 8.1, unpatched. Apply mitigations now. https://www.valtersit.com/cve/CVE-2026-11727/ #CVE #infosec #IBM
Overview
- IBM
- Guardium Data Protection
Description
Statistics
- 1 Post
Fediverse
CVE-2026-84108: IBM Guardium Data Protection 12.2 RCE via improper input neutralization. CVSS 8.1, unpatched. Patch now. https://www.valtersit.com/cve/CVE-2026-84108/ #CVE #infosec #IBM
Overview
Description
Statistics
- 1 Post
Fediverse
CVE-2026-71418: Suricata DoS, CVSS 7.5. DNS-over-HTTP/2 buffer flaw causes quadratic CPU use, degrading packet processing. Unpatched as of now - update immediately. https://www.valtersit.com/cve/CVE-2026-71418/ #CVE #Suricata #infosec