SharePoint RCE Exploited, One-Click WordPress Hack, Shai-Hulud Returns, and More

THN Daily Updates
Newsletter
cover

Cybersecurity Auditing: Principles, Practices, and Frameworks ($115.00 Value) FREE for a Limited Time

Practical guide to cybersecurity controls, systems, programs, and management.

Download Now Sponsored
LATEST NEWS Sep 26, 2026

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponizati...

Read More
Twitter Facebook LinkedIn

Zero Trust for AI Agents Starts With Fixing Zero Visibility

The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much product...

Read More
Twitter Facebook LinkedIn

Zero-Copy Databricks Access to On-Prem Data, Enforced at the Storage Layer

Regulated data can now stay exactly where compliance requires while Databricks queries it live. MinIO AIStor enforces read-only access at the storage layer—no replication, no data leaving your environment. See the architecture in the technical blog.

Read More
Twitter Facebook LinkedIn

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control o...

Read More
Twitter Facebook LinkedIn

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evide...

Read More
Twitter Facebook LinkedIn

Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. "Kiteworks ...

Read More
Twitter Facebook LinkedIn

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected Git...

Read More
Twitter Facebook LinkedIn

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to ...

Read More
Twitter Facebook LinkedIn
cover

Cybersecurity Auditing: Principles, Practices, and Frameworks ($115.00 Value) FREE for a Limited Time

Practical guide to cybersecurity controls, systems, programs, and management.

Download Now Sponsored

This email was sent to sikubaycom.s3cr3tz@blogger.com. You are receiving this newsletter because you opted-in to receive relevant communications from THN. To manage your email newsletter preferences, please click here.

Contact THN: info@thehackernews.com
Unsubscribe

THN | K.P BLock, Pitampura, Delhi