Malware Activity
Infostealer Malware Exposes Thousands of Enterprise AI Accounts
Infostealer malware is increasingly exposing enterprise AI accounts, creating risks that extend beyond traditional credential theft by giving attackers access to conversation histories, active sessions, API keys, automation capabilities, and billable resources. SOCRadar analyzed more than one million infostealer records associated with AI services across over 80,000 corporate domains, narrowing its research to 482 major enterprises and identifying 5,434 records linked to 1,500 distinct corporate email addresses; 295 organizations had appeared in stealer logs within the previous 90 days. ChatGPT/OpenAI accounted for the overwhelming majority of exposure, appearing at 358 companies and representing roughly 90% of records, while developer and automation platforms including Hugging Face, Replit, Zapier, and Notion were also affected. Technology and internet services companies recorded the greatest exposure, though financial services, healthcare, energy, retail, and industrial organizations were also impacted. Stolen session cookies are particularly concerning because they can potentially allow attackers to bypass MFA and access sensitive prompt histories, while compromised automation sessions may inherit existing OAuth permissions and stolen API keys can enable unauthorized usage and “LLMjacking.” The findings highlight shadow AI and unmanaged endpoints as significant enterprise risks and recommend organizations discover unauthorized AI accounts, enforce SSO and shorter-lived sessions, rotate and restrict API keys, monitor for anomalous session reuse, and treat employees appearing in infostealer logs as potential endpoint compromises rather than simply resetting their passwords.
Threat Actor Activity
ShinyHunters Bypass WAFs to Resume Mass Exploitation of Oracle PeopleSoft Flaw
ShinyHunters (also tracked by Google as UNC6240) has resumed mass exploitation of Oracle PeopleSoft’s Environment Management Hub via CVE-2026-35273 (CVSS score: 9.8), using a simple URL‑encoding trick to bypass web application firewalls. Many organizations that could not patch immediately relied on WAF rules blocking /PSEMHUB/*. ShinyHunters now requests /%50SEMHUB/ (percent‑encoding the “P”), which many WAFs compare before decoding, while Oracle WebLogic decodes it and still routes to the vulnerable servlet. Researchers warn that the group can vary encodings and case, so string‑based WAF rules are unreliable. The renewed campaign targets higher education, technology, IT services, healthcare, agriculture, transportation, and government. The attack chain sends serialized Java objects to /%50SEMHUB/hub to fingerprint hosts, then abuses Java deserialization to drop JSP web shells (x.jsp for command execution, u.jsp/u2.jsp for chunked uploads). From there, ShinyHunters uploads a trojanized “Ple64.exe” that loads SIDEEYE, a C++ backdoor supporting credential theft, file and process management, reverse shells, and reverse proxying. They also deploy Neo‑reGeorg tunneling (tunnel.jsp/.jspx) to route SOCKS5 traffic over HTTP/HTTPS and use MeshAgent RMM for persistent access on Linux. Researchers also note that about a quarter of commands run as root or NT AUTHORITY\SYSTEM, giving full OS control. UNC6240 follows a consistent pattern of data‑theft extortion, such as stealing HR, payroll, student, and other records, then threatening to leak them if ransoms are not paid. In line with security recommendations, CTIX Analysts recommend that organizations patch CVE‑2026‑35273, disable or remove PSEMHUB where possible, search WebLogic logs for /PSEMHUB/ and encoded variants, inspect PSEMHUB.war for web shells, rotate credentials, review database audit logs for bulk exports, and monitor outbound traffic from PeopleSoft hosts, as opposed to purely relying on WAF rules alone.
- Bleeping Computer: ShinyHunters Exploit Oracle PeopleSoft Article
- The Hacker News: ShinyHunters Exploit Oracle PeopleSoft Article
Vulnerabilities
CISA Orders Emergency Action as Two Citrix NetScaler Zero-Days Face Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure vulnerable Citrix NetScaler systems by September 30, 2026, after Citrix confirmed active global exploitation of two (2) critical zero-day vulnerabilities, both rated CVSS 9.5/10. CVE-2026-88771 is an improper input validation flaw affecting all NetScaler ADC and Gateway deployments that allows unauthenticated arbitrary command execution, while CVE-2026-88772 is a memory overflow vulnerability enabling remote code execution (RCE) or denial-of-service (DoS) when DTLS is enabled, which is the default on VPN virtual servers. Technical analysis from watchTowr found that CVE-2026-88771 involves unsafe command construction in the ns_monuploadd_err.pl Perl script, allowing attacker-controlled data supplied through a pre-authentication endpoint to ultimately execute commands as root. Citrix released fixes in NetScaler and corresponding supported FIPS/NDcPP releases, while end-of-life 12.1 and 13.0 installations should migrate to supported versions. Prior to public disclosure, cybersecurity organizations and national agencies reportedly warned customers to prepare for emergency remediation after exploitation was detected at multiple organizations worldwide, with one (1) vulnerability reportedly capable of placing shellcode directly into memory. CISA added both flaws to its Known Exploited Vulnerabilities (KEV) Catalog, while Citrix provided generic indicators of compromise and advised potentially affected organizations to preserve forensic evidence, isolate compromised appliances, rotate credentials and encryption keys, investigate connected systems, and rebuild affected devices. With more than 23,000 Internet-exposed systems displaying NetScaler fingerprints, the vulnerabilities present a significant attack surface, particularly because NetScaler appliances commonly operate as Internet-facing edge devices that can provide attackers an initial foothold into internal corporate networks. CTIX analysts urge any affected administrators to follow the Citrix/CISA guidance to prevent exploitation.
- Bleeping Computer: CVE-2026-88771, CVE-2026-88772 Article 1
- Bleeping Computer: CVE-2026-88771, CVE-2026-88772 Article 2
The Hacker News: CVE-2026-88771, CVE-2026-88772 Article
📧 Never Miss a Briefing
Stay informed and secure. Subscribe to Ankura’s Cyber Flash Update, a bi-weekly briefing curated by our top cybersecurity experts. Receive timely insights on emerging threats, vulnerabilities and malicious actors to keep your systems secure.
Join the Cyber Flash Update community today.
© Copyright 2026. The views expressed herein are those of the author(s) and not necessarily the views of Ankura Consulting Group, LLC., its management, its subsidiaries, its affiliates, or its other professionals. Ankura is not a law firm and cannot provide legal advice.
