ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack

2026-09-23T14:51:38Z•d54ce2a18e37c383c37e2923aa6d5f89f35adb0385c6c6ae338851f58b0af7ad
CVE-2026-7273CVE-2026-87902CVE-2026-93616Check-PointGDPRMicrosoft-DefenderNorth-Korea-linkedVeeamWordPressZyxelactively-exploitedbuffer-overflowcybercrimedata-breachdefense-evasiondevice-code-phishingfile-inclusioninfostealerknown-exploited-vulnerabilitypath-traversalphishing-as-a-serviceprivilege-escalationproof-of-conceptremote-code-executionsupply-chainvulnerabilityzero-day

What happened

Security Affairs reports multiple September 2026 cybersecurity developments, including alleged breaches, phishing and infostealer campaigns, actively exploited vulnerabilities, public proof-of-concept exploits, and regulatory enforcement. High-priority items include an unauthenticated WordPress local file inclusion vulnerability enabling remote code execution (CVE-2026-87902), an actively exploited unauthenticated Check Point Security Management Server path traversal flaw allowing script upload and execution (CVE-2026-93616), and a CISA KEV-listed Zyxel switch buffer overflow (CVE-2026-7273).

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
d54ce2a18e37c383c37e2923aa6d5f89f35adb0385c6c6ae338851f58b0af7ad
Enrichment time
2026-09-23T14:51:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.