By security practitioners, for security practitioners novacoast federal | Apex Program | novacoast | about innovate
By security practitioners, for security practitioners

Top 10 Cybersecurity News (September 28, 2026): ShinyHunters Claims FBI Breach Via PeopleSoft Zero-Day, CISA Flags Exploited WSO2, Adobe Commerce, SharePoint Flaws, and More

WEEKLY TOP TEN: September 28, 2026, 16:00 GMT

  1. ShinyHunters Claims FBI Breach Via PeopleSoft Zero-Day

    The ShinyHunters extortion gang claims it breached FBI systems by exploiting a new, unpatched Oracle PeopleSoft zero-day. It says it then moved laterally into FBI-managed AWS GovCloud infrastructure. The group claims it stole 2TB to 3TB of data on current and former employees and job applicants. It also claims it compromised Criminal Justice, HR and Medlink services, and it shared a screenshot of a defaced apply.fbijobs.gov page. The FBI confirmed it is investigating claims of unauthorized activity affecting FBIjobs.gov. ShinyHunters says the attack retaliates for a May FBI FLASH report and that it is now using the same flaw against Fortune 500 companies..
  2. F5 BIG-IP APM Zero-Day Exploited For Remote Code Execution

    F5 and CISA warned that attackers exploited CVE-2026-94127 as a zero-day. It is a critical BIG-IP Access Policy Manager flaw rated 9.8. Unauthenticated attackers can achieve remote code execution by sending malicious traffic when an APM access policy and an OAuth profile are configured on a virtual server. The flaw is exposed only when APM acts as an OAuth Authorization Server, and appliance mode is also vulnerable. Affected versions are 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3. F5 has released hotfixes and three indicators of compromise. CISA added the flaw to its Known Exploited Vulnerabilities catalog with a three-day federal patching deadline.
  3. Check Point Management Server Zero-Day Hit In Attacks

    Check Point released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in Security Management Server that attackers are already exploiting. Unauthenticated attackers can use it to upload and run malicious scripts. It also affects Multi-Domain Security Management, Log Server, Multi-Domain Log Server and SmartEvent. Check Point says a handful of customers have been attacked and has published indicators of compromise. The fix ships in the R82.20 Security Hotfix. Where patching must wait, Check Point recommends limiting access to trusted IP addresses through SmartConsole’s Trusted Clients setting. CISA added the flaw to its KEV catalog alongside CVE-2026-85102, a separate Check Point VPN certificate flaw.
  4. CISA Flags Exploited WSO2, Adobe Commerce, SharePoint Flaws

    CISA added two critical flaws to its Known Exploited Vulnerabilities catalog. The first is CVE-2026-5430, a maximum-severity JWT authentication bypass in WSO2 API Manager, API Control Plane, Traffic Manager and Universal Gateway. The second is CVE-2026-71362, an incorrect authorization bug in Adobe Commerce and Magento. The WSO2 flaw accepts tokens signed with an unsupported algorithm, which lets attackers take over admin accounts, and honeypots captured forged tokens on September 13. CISA also flagged active exploitation of a Microsoft SharePoint code injection flaw, CVE-2026-65660, and a MikroTik RouterOS SSH bypass. WSO2 serves nearly 1,000 customers in banking, government, telecom and logistics.
  5. Arista Patches Exploited VeloCloud Orchestrator Zero-Day

    Arista Networks patched CVE-2026-93952, a maximum-severity improper input validation flaw in on-premises VeloCloud Orchestrator that attackers exploited as a zero-day. Remote, unauthenticated attackers can reach privileged internal functionality and compromise the orchestrator and the SD-WAN data it manages. That access could extend to managed Edge devices. Exposure applies where certificate-based authentication between Edge devices and the orchestrator is configured. Fixed builds are out for some release trains, while others are still pending. CISA added the flaw to its KEV catalog on September 22. It is the second exploited VeloCloud Orchestrator zero-day this year, following July’s CVE-2026-16812.
  6. Kiteworks Urges Global Server Shutdown Over Attack Threat

    Kiteworks, a secure file-sharing vendor, urged customers worldwide to shut down their servers for six hours on Saturday, September 26. The company said it had received credible threat intelligence from federal authorities that an attack on customer systems may be imminent. It recommended taking systems offline even if they are not directly internet-facing. Kiteworks says it knows of no compromise, that all known vulnerabilities are fixed in version 9.5.1, and that the advisory is precautionary. Support staff reportedly said the goal was to guard against possible zero-day attacks. Enterprise file-transfer platforms have long been prime targets for data-theft extortion groups such as Clop.
  7. Roundcube Webmail SQL Injection Flaw Now Exploited

    Canada’s Centre for Cyber Security updated its advisory on September 21 to warn that attackers are exploiting CVE-2026-48842 in Roundcube Webmail. It is a pre-authentication SQL injection flaw in the virtuser_query plugin. A preg_replace() backslash escape bypass lets unauthenticated attackers inject SQL against the backing database. The flaw is rated 8.1 and affects Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1, which were released in May. Four months passed between the patch and confirmed exploitation, which shows how long exposed webmail servers stay unpatched. Webmail has been a recurring target for espionage groups, so administrators should update and review database access logs immediately.
  8. AI Agent Campaign Steals 600,000 Cards From Retailers

    A financially motivated attacker used three open-source AI agent tools to break into hundreds of online retailers and other organizations. The operator stole more than 600,000 credit card records and planted card-skimming code, at trivial cost. AI security company Gambit recovered the operator’s staging server and reconstructed the campaign. Victims include a Fortune 500 hospitality company, a major US airline, a large private US industrial supplies distributor and a US online fashion retailer. More than 25 other organizations were also breached. The agents handled vulnerability research, exploitation and orchestration, so a single operator could run e-commerce attacks at a scale that once needed a team.
  9. Ransomware Gangs Now Exploiting JetBrains TeamCity Flaw

    CISA updated its KEV catalog on September 23 to flag that ransomware gangs are now exploiting CVE-2026-63077. It is a critical JetBrains TeamCity On-Premises flaw rated 9.8. Unauthenticated attackers can abuse the agent polling protocol to run operating system commands. That exposes stored credentials and configurations and puts the integrity of builds and downstream CI/CD pipelines at risk. JetBrains patched the flaw on July 25 in versions 2025.11.7 and 2026.1.3. Shadowserver still tracks about 160 unpatched internet-exposed servers, down from roughly 700. All four TeamCity flaws CISA has tagged as exploited since October 2023 have been used in ransomware attacks.
  10. Chinese Hackers Hit Zyxel Switches, Steal Government Data

    GreyNoise reported that a Chinese-speaking threat actor linked to the Red Heron group exploited Zyxel GS1900 Smart Managed Switches and WordPress to steal sensitive data. Since August 17, the actor has used CVE-2026-7273 to compromise 996 Zyxel switches in 48 countries. It pulled device configurations, network details and hashed root credentials. Earlier, the same actor used wp2shell WordPress core flaws to breach at least 49 organizations in 29 countries. At one Western government organization, it stole 18,566 records containing plaintext passwords and personal data tied to government and law enforcement agencies. CISA added the Zyxel flaw to its KEV catalog on September 21.

Our Threat Operations and Intelligence team compiles a daily digest of the most recent online cybersecurity risks. The previous 10 stories were determined to be most significant during the course of the week, ranked by highest risk, and using multiple sources when available.

Previous Post

Architecting Security Operations For AI-Powered Attacks

Innovate uses cookies to give you the best online experience. If you continue to use this site, you agree to the use of cookies. Please see our privacy policy for details.