Weekly review

ThreatNoir Weekend Brief — September 27

2026-09-27Morning5 articles
Audio
Listen to the episode

Morning Review in IT Security — September 27, 2026

The threat landscape continues to evolve with multiple critical developments affecting enterprise security posture. Today's review covers sophisticated WAF bypass techniques targeting Oracle infrastructure, credential-stealing malware leveraging vulnerable drivers, compromised open-source tooling remaining active in production environments, and emerging risks in AI-powered applications alongside a significant Microsoft update rollback.

ShinyHunters Uses WAF Bypass Trick in Oracle PeopleSoft Attacks

The ShinyHunters extortion gang has developed a URL-encoding technique to circumvent web application firewall protections designed to mitigate the Oracle PeopleSoft CVE-2026-35273 vulnerability. This bypass allows threat actors to resume widespread exploitation against unpatched servers, demonstrating the ongoing cat-and-mouse game between defenders implementing WAF rules and attackers refining their delivery mechanisms. Source: ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

The identified malware components include Ple64.exe, u.jsp, u2.jsp, and x.jsp, indicating a multi-stage attack chain designed to establish persistence on compromised systems. Organizations running Oracle PeopleSoft must prioritize patching efforts and review WAF configurations to account for encoding variations that attackers may employ.

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

Psychedelic Stealer, distributed through compromised Ukrainian websites using ClickFix-style Cloudflare verification checks, operates as part of a broader malware-as-a-service platform called Lunex. Researchers at Ontinue identified a four-stage attack chain specifically targeting Ukrainian-speaking users, beginning with a fake CAPTCHA page that initiates the infection sequence. Source: Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

The attack exploits CVE-2023-20598, a vulnerable AMD driver, to disable security monitoring tools and evade detection while harvesting browser credentials. This technique represents a significant escalation in sophistication, as threat actors leverage legitimate driver vulnerabilities to blind endpoint protection mechanisms. The infrastructure associated with this campaign includes IP address 193.178.159.128.

GitHub Actions Re-enabled with Mini Shai-Hulud Payload Still Active

Two third-party GitHub Actions that were previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainers while still containing malicious code. The actions remained accessible for more than a week despite continuing to point to malicious payloads, creating an extended window of exposure for developers who relied on these tools in their CI/CD pipelines. Source: GitHub Actions re-enabled with Mini Shai-Hulud payload still active

This incident highlights the critical importance of thorough security audits before re-enabling compromised open-source components and the need for better coordination between maintainers and the security community when addressing supply chain incidents.

Placeholder Domains Used by 349 AI Agent Skills Found Redirecting to Scams

Manifold Security discovered that placeholder domains referenced in 359,000 GitHub files and integrated into 349 AI agent skills have been hijacked to serve cloaked scam content. This represents a novel attack vector targeting developers who incorporate AI agent skills into their applications without validating the underlying domain infrastructure. Source: Placeholder Domains Used by 349 AI Agent Skills Found Redirecting to Scams

The widespread presence of these malicious domains across GitHub repositories demonstrates how supply chain risks have expanded into the AI tooling ecosystem, affecting both developers and end users who interact with compromised AI agents.

Microsoft Pauses KB5002907 Update After Office License Deactivations

Microsoft has halted the rollout of the KB5002907 Microsoft 365 update following widespread reports that the patch deactivated or completely removed perpetual Office 2016 and Office 2019 installations. This decision reflects the critical importance of thorough testing before deploying updates that interact with licensing systems. Source: Microsoft pauses KB5002907 update after Office license deactivations

Organizations that have already applied this update should assess whether their Office installations have been affected and consider reverting to previous versions pending a corrected release from Microsoft.

Today's threat intelligence underscores the necessity of maintaining comprehensive patch management programs, implementing defense-in-depth strategies against WAF bypasses, conducting rigorous audits of open-source dependencies, and exercising caution when adopting emerging AI-powered tools in production environments.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
CVE1
  • Oracle PeopleSoft vulnerability exploited by ShinyHunters.
Malware4
  • Ple64.exe
    Executable deployed by ShinyHunters on Windows servers.
  • u2.jsp
    Web shell deployed by ShinyHunters for file uploads.
  • u.jsp
    Web shell deployed by ShinyHunters for file uploads.
  • x.jsp
    Web shell deployed by ShinyHunters for command execution.