Articles 2 min read

Cyber Matters: Edition 1

Cutting through the noise to highlight the developments most likely to affect your organization: the threats worth acting on and the incidents worth learning from.

What Actually Matters This Cycle

Executive Snapshot

This cycle in one line: Attackers are going straight at the systems that hold people data, from HR and recruiting platforms to court records and a Pentagon personnel server, and many of the worst exposures trace back to workarounds and patches that were never fully put in place.

Overall risk this cycle: ELEVATED

Actively exploited flaws span Oracle PeopleSoft, SharePoint, routers, web platforms and network switches; four fresh incidents show attackers targeting people data; and several of the worst exposures trace back to fixes that were never fully applied.

Emergent Cyber Threats

New and evolving attack methods to be aware of and steps to reduce your exposure.

Google’s Mandiant and Threat Intelligence Group reported on September 25 that ShinyHunters has resumed widespread attacks on Oracle PeopleSoft servers through CVE-2026-35273, a flaw that allows unauthenticated remote code execution. The group first exploited it as a zero-day between May and June, and Oracle fixed it in June. Many organizations never installed the fix. Instead, they used a web application firewall rule to block the vulnerable “/PSEMHUB/” path. The attackers now simply encode one letter of that path (“/%50SEMHUB/”), which slips past many firewall rules while the server still routes the request to the vulnerable endpoint. BreachNews, citing Google, reports web shells on dozens of systems across government, healthcare, higher education, technology, transportation, and agriculture.

WHAT TO DO
  • Install Oracle’s security update for CVE-2026-35273 on every PeopleSoft environment. Do not rely on firewall rules alone.
  • If you must keep a firewall rule for now, make sure it decodes and normalizes requests before matching, and blocks encoded and mixed-case variants.
  • Search WebLogic access logs for encoded or unusual requests to PSEMHUB, and hunt for web shells on PeopleSoft servers.
  • Treat any confirmed PeopleSoft compromise as an HR and payroll data breach and preserve evidence before rebuilding.
  • Review other “temporary” mitigations you have in place and set a date to replace each one with the real fix.

Source: BleepingComputer (Lawrence Abrams), September 26, 2026; BreachNews, updated September 26, 2026

On September 25, CISA added two actively exploited flaws to its Known Exploited Vulnerabilities (KEV) catalog. The first, CVE-2026-65660 (CVSS 8.8), is a SharePoint flaw that Microsoft originally described as spoofing. Microsoft has since said it allows remote code execution, and that as of September 25 it “had reliable evidence of observed attacks.” The second, CVE-2026-67279, is a MikroTik RouterOS flaw. Attackers chain it with a second RouterOS flaw (CVE-2026-86060) in an exploit called “MikroTrick.” CERT Polska said the combination gives “full unauthenticated access to the administrative console” of internet-exposed routers. The lesson on SharePoint is simple: a vendor’s first severity label can be wrong, so patch on exploitation evidence, not on the label.

WHAT TO DO
  • Apply Microsoft’s fix for CVE-2026-65660 to every on-premises SharePoint server, starting with internet-facing ones.
  • Review SharePoint servers for unexpected files, new administrator accounts, and unusual outbound connections.
  • Update MikroTik RouterOS and remove internet access to router management interfaces.
  • Check the configuration of any internet-exposed MikroTik device for unauthorized changes and rotate its credentials.
  • Re-prioritize patches when a vendor changes a flaw’s impact, not just when it is first published.

Source: The Hacker News (Ravie Lakshmanan), September 26, 2026; CISA Alert, September 25, 2026

CISA also listed three exploited flaws in widely used web platforms. CVE-2026-5430 (CVSS 9.8) is in WSO2 API Manager and related gateway products and can lead to remote code execution. According to watchTowr, attackers were exploiting it against its honeypots from at least September 13, weeks before the KEV listing. WSO2 is used by nearly 1,000 customers across banking, government, telecommunications, and logistics. CVE-2026-71362 (CVSS 9.1) in Adobe Commerce and Magento lets an attacker switch a shopper’s session into another customer’s account. CISA also added CVE-2026-87902, a remote file inclusion flaw in WordPress Core. As watchTowr put it, by the time a flaw reaches the KEV list, attackers may already have had “days, or, in this instance, weeks, to act.”

WHAT TO DO
  • Patch WSO2 API gateways and management products now, and review them for unexpected, uploaded files.
  • Update Adobe Commerce and Magento storefronts, and watch for customers reporting account or order changes they did not make.
  • Update WordPress Core on every site, including marketing and campaign sites run by agencies.
  • Keep an inventory of internet-facing web platforms and who owns each one, including sites outside central IT.
  • Subscribe to threat-intelligence feeds so you can act on exploitation reports before the KEV listing arrives.

Source: The Hacker News (Ravie Lakshmanan), September 25, 2026; CISA Alert, September 25, 2026

Two KEV additions this period were for flaws that already had patches. On September 21, CISA confirmed attacks on Zyxel GS1900 network switches (CVE-2026-7273), which let an attacker on the local network run commands without logging in. Zyxel shipped the fix on June 16, and GreyNoise first saw exploitation on September 17. On September 19, CISA added three Linux kernel flaws, including CVE-2025-39682 (CVSS 9.8). Red Hat called one of them high risk with “known public exploits.” Attackers keep succeeding against fixes that exist but were never applied.

WHAT TO DO
  • Upgrade Zyxel GS1900 switch firmware to the fixed version on every affected model.
  • Bring switches, routers, and other network gear into the same patch cycle as servers.
  • Apply vendor kernel updates to Linux servers, prioritizing shared and internet-facing systems.
  • Report “patch available but not applied” as a standing risk metric to leadership.

Source: BleepingComputer (Sergiu Gatlan), September 22, 2026; The Hacker News (Ravie Lakshmanan), September 19, 2026

Black Kite’s manufacturing and distribution ransomware report, released September 17, found that manufacturers made up 22% of ransomware victims from April 2025 through March 2026. That makes manufacturing the most-targeted industry for the fifth straight year. Incidents rose about 40% year over year, to 1,183 in the first seven months of 2026, and half came from groups that did not exist two years ago. The report says attackers pick targets from “externally visible signals, from unpatched systems and exploitable services to leaked credentials,” and warns that “a large manufacturer’s vendor list is its attack surface.”

WHAT TO DO:
  • If you manufacture or distribute, test how long you can keep operating if production systems go down.
  • Separate plant-floor (operational technology) networks from office IT.
  • Rank suppliers by observable risk signals, not only by spend or tier.
  • Close the exposed services and leaked credentials that attackers use to choose their targets.
  • Keep offline, tested backups of production, ERP, and logistics systems.

Source: SecurityWeek (Kevin Townsend), September 17, 2026; Infosecurity Magazine (James Coker), September 18, 2026

Recent Incidents

Real-world breaches and the lessons they carry for organizations like yours.

A breach notice dated September 18 and reported by Military Times on September 24 shows that unauthorized users accessed files on a Defense Manpower Data Center (DMDC) server between October 2025 and July 16, 2026. The server held unencrypted Social Security numbers and other personal details, and the access came through a flaw in a file-sharing system. Depending on the person, the exposed data included names, dates of birth, contact information, and military occupational specialty. The Pentagon has not confirmed a count. Two people familiar with the incident estimated that about four million Defense Department personnel may be affected. Affected individuals are being offered one year of credit monitoring. The failures are basic ones: sensitive data stored unencrypted, and a nine-month gap before anyone detected access.

WHAT TO DO:
  • Encrypt sensitive personal data at rest, especially on file-sharing and file-transfer servers.
  • Inventory file-sharing and file-transfer systems, and patch or retire any that are internet-facing.
  • Alert on unusual access to bulk personnel files, and review those alerts regularly.
  • If you employ veterans, reservists, or defense contractors, warn staff about targeted phishing that uses their service details.

Source: Military Times (Natalie Oliverio), September 24, 2026; CNN via Yahoo News, September 25, 2026

On September 22, ShinyHunters defaced the FBI’s job-application site (apply.fbijobs.gov). The group claims it used a new Oracle PeopleSoft zero-day to get in, then moved into FBI-managed AWS GovCloud systems and took 2 to 3 terabytes of data on current and former employees and job applicants. The FBI confirmed it is investigating claims of unauthorized activity affecting FBIJobs.gov. It has not confirmed data theft, and it has not determined whether the entry point was a third-party provider or its own system. Reporters verified parts of a sample of roughly 5,000 purported employee records. Neither the FBI nor Oracle has confirmed the new zero-day. The group says it acted in retaliation for an FBI advisory about it, and that it now targets Fortune 500 companies.

WHAT TO DO:
  • Confirm who hosts and patches your recruiting and HR portals, including those run by third-party providers.
  • Keep applicant and employee data out of internet-facing systems unless it truly needs to be there.
  • Separate recruiting portals from core HR, payroll, and cloud environments so one compromise cannot reach them all.
  • Prepare a playbook for public extortion and defacement, including who speaks for the organization and when.

Source: BleepingComputer (Lawrence Abrams), September 22, 2026; Infosecurity Magazine (Phil Muncaster), September 23, 2026

On September 25, Arizona Supreme Court Chief Justice Ann Scott Timmer announced that “criminal hackers or their bots” attacked the state court system and are believed to have copied “personally identifiable information about many Arizonans.” The courts have not said which courts or databases were affected or how many people were involved, and the FBI is investigating. Notices went out from an official court address. Some recipients have current or former protective orders, and their confidential addresses may be among the copied data. The court says it has no evidence that the data has been shared. The case shows that the harm from a breach depends on who the data describes, not just how many records were taken.

WHAT TO DO:
  • Identify which of your records could put someone at physical risk if exposed, such as protected addresses, and apply the strongest controls to them.
  • Tell people how you will notify them after an incident, so scammers cannot easily imitate your notices.
  • If you work with court or case-management vendors, ask them what data they hold and how they protect it.
  • Plan victim-support steps, not just credit monitoring, for data whose exposure carries safety risks.

Source: Cybernews (Anna Zhadan), September 27, 2026; Arizona Republic via Yahoo News (Rey Covarrubias Jr.), September 26, 2026

In a Form 8-K filed with the SEC on September 14, Houston-based utility CenterPoint Energy confirmed that “an unauthorized third party obtained personal information relating to a portion of the Company’s customers through one of the Company’s external-facing systems.” The attacker, using the alias “4d722e4d656f77,” claims to have taken 7.49 million records, including names, addresses, account numbers, billing amounts, and partial Social Security numbers, by cycling through customer IDs on a public API that had no rate limiting or web application firewall. CenterPoint has not confirmed the count and says electric, and gas services were not affected.

WHAT TO DO:
  • Inventory every public API, and require authentication, rate limiting, and monitoring on each one.
  • Test APIs for sequential or guessable IDs that let one user read another user’s records.
  • Warn staff and customers to expect utility-themed phishing that uses real account details.
  • Treat utilities and other critical-infrastructure providers as high-risk third parties in your vendor program.

Source: BleepingComputer (Bill Toulas), September 15, 2026; SecurityWeek (Eduard Kovacs), September 15, 2026

The Bottom Line

Three themes tie these two weeks together. First, workarounds expire: ShinyHunters returned to PeopleSoft by encoding a single letter, and Zyxel and Linux flaws were exploited months after fixes shipped. Second, people data is the prize, and attackers took it from a recruiting portal, a court system, a utility API, and a Pentagon personnel server. Third, detection time decides the damage: the DMDC access ran for about nine months, and watchTowr saw WSO2 attacks weeks before the flaw reached the KEV list.

Three Actions to Take Right Now

1. Install the real Oracle PeopleSoft and Microsoft SharePoint fixes, and stop relying on firewall-only workarounds.

2. Put authentication, rate limiting, and monitoring on every public API and portal that touches personal data.

3. Encrypt sensitive personal data at rest, and alert on bulk access to it.

The takeaway: Prioritize actively exploited vulnerabilities, strengthen authentication, maintain tested backups, limit access to sensitive data and make sure your incident-response plan is ready before you need it.

Withum plus signs.

Have Questions or Need Guidance?

Want help assessing how these developments could affect your organization? Withum’s Risk Advisory and Assurance Services Team can help identify potential exposure and prioritize next steps.

Contact Us

Related Insights

Read more
business leaders analyzing cybersecurity risk
What Every Business Leader Should Know About Cyber Risk Today

Cyber threats have changed significantly in just a few years. Attackers are increasingly using legitimate credentials rather than trying to break through traditional security controls. Cloud platforms, third-party relationships and expanding digital ecosystems have created more ways to access an organization’s systems and data. Artificial intelligence is making social engineering faster and more convincing. At…

Read more
two cybersecurity professionals reviewing a security dashboard.
Why Managed IT Is a Business Strategy, Not Just a Help Desk

For small and midsize businesses (SMBs), technology has become fundamental to nearly every part of the business, from serving customers and processing payments to managing data and keeping operations running. Yet many businesses still approach IT reactively, addressing issues when something breaks rather than managing technology as critical business infrastructure. Artificial intelligence is making that…

Read more
Gears icon on a digital display with reflection. Concept of business process workflow.
How Oversight Gaps Can Develop in Multiemployer Plans

Even in well-run multiemployer plans (“Plans”), oversight gaps can quietly grow over time. In many cases, these gaps are not the result of negligent or disengaged Boards. Rather, they emerge when too much reliance is placed on existing systems, familiarity and routine reduce visibility into how processes actually operate, or technical complexity discourages questions and…