ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
2026-09-22T19:23:22Z•9db21826d7f8464d21e68047fba78c6e065137616856b44b6cf1531e019ced93
CVE-2026-86296AI-assisted malwareBigCommerceCISACSRFCheck PointClosedQuorumD-Link DIR-822AFBILinux kernelMicrosoft accountsOracle PeopleSoftPHP code executionShinyHuntersWindows DefenderWindows malwareWordPressZyxel GS1900active exploitationdata theftphishing-as-a-serviceransomware/extortionshadow ITsupply-chain compromisezero-day
What happened
A BleepingComputer security-news feed covering multiple significant developments, including alleged ShinyHunters exploitation of an Oracle PeopleSoft zero-day against FBI systems, actively exploited Check Point, Zyxel, Linux kernel, D-Link, Windows Defender, and WordPress vulnerabilities, an AI-enabled Windows malware called ClosedQuorum, the EvilTokens phishing-as-a-service disruption, and third-party credential abuse affecting BigCommerce merchants. Several items involve zero-days, public exploit code, active exploitation, or potential data theft.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 9db21826d7f8464d21e68047fba78c6e065137616856b44b6cf1531e019ced93
- Enrichment time
- 2026-09-22T19:23:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.