left cover bg
circles

Security Daily.

Sunday, September 27, 2026

Automatically Curated Security Digest

Collected

5 Articles

Across

1 Trusted Sources

Published

Last Updated 11:59 AM UTC

Coverage

BleepingComputer
Top Story

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

BleepingComputerHigh

Why it matters

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread…

Read Original

5

Articles

1

Sources

1

CVEs

0

Alerts

0

Research

1m

Read Time

Feed Status

CISA2
NIST NVD
BleepingComputer13
PortSwigger Research

Automated Security Digest — This page is an automatically curated cybersecurity digest generated from publicly available security feeds. All articles remain the property of their respective publishers. Click any item to read the original article.

Last generated: Sep 27, 2026, 11:59 AM

Jump to Section

Cybersecurity News

5

Latest news from trusted cybersecurity publications.

BleepingComputerCybersecurity NewsHigh

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. [...]

CVE-2026-35273
Read Original
BleepingComputerCybersecurity News

Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer

Anthropic's Claude Opus 5.5 appears to be changing how it writes, with new analysis showing fewer obvious AI writing patterns, shorter sentences, and simpler wording compared with Opus 5. [...]

Read Original
BleepingComputerCybersecurity News

Microsoft pauses KB5002907 update after Office license deactivations

Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations. [...]

Read Original
BleepingComputerCybersecurity News

GitHub Actions re-enabled with Mini Shai-Hulud payload still active

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. [...]

Read Original
BleepingComputerCybersecurity News

OpenAI's AI agents accidentally uploaded user-provided images to third-party sites

OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks. [...]

Read Original

Share This Digest