Cybersecurity Weekly Briefing, 2 October
ShinyHunters resumes mass exploitation of Oracle PeopleSoft by bypassing WAF rules
Mandiant and Google Threat Intelligence Group have detected a new wave of exploitation of CVE-2026-35273 (CVSSv3 9.8) in Oracle PeopleSoft attributed to ShinyHunters, which had already used the vulnerability as a zero-day against universities. The actor has adapted its exploit to evade WAF rules blocking the vulnerable Environment Management Hub endpoint by partially encoding the request path, allowing WebLogic to continue processing it.
After abusing Java deserialization, the attackers deploy the x.jsp and u.jsp webshells, execute commands without writing to disk and use tools such as SIDEEYE, Neo-reGeorg and MeshAgent for persistence and traffic tunnelling. The campaign has compromised dozens of systems across higher education, technology, IT services, healthcare, transportation, agriculture and public administration.
Organisations are advised to apply Oracle’s patch, disable EMHub where it is not required and inspect WebLogic nodes for unexpected .jsp or .exe files.
JADEPUFFER destroys Azure resources using compromised service principals
Microsoft has documented a destructive JADEPUFFER campaign in which the actor used two compromised service principals from the same Azure tenant. Following approximately 15 hours of reconnaissance involving more than 300 read operations, the second principal executed over 150 destructive or credential-harvesting actions in around seven minutes, including more than 100 attempts to delete Storage accounts, as well as a Key Vault, a Function App and an App Service plan.
The actor also attempted to remove Azure Site Recovery and Azure Backup protections and later extracted access keys from more than 30 storage accounts. Microsoft assesses the activity as consistent with a ransomware or extortion scenario, although no ransom note was observed.
Organisations should rotate exposed secrets, enforce least privilege through Azure RBAC, protect backups with independent controls and monitor for large-scale ListKeys requests.
Operation Master exploits GlobalProtect and AdaptixC2 to feed an industrial-scale fraud platform
STRU researchers have documented Operation Master, a cybercrime operation that exploited CVE-2026-0257 (CVSSv3 9.1), an authentication bypass affecting Palo Alto Networks GlobalProtect with confirmed active exploitation.
The operation used an automated workflow that scanned 277.5 million addresses and selected 81 organisations, combining VPN access with SQL injection, abuse of xp_cmdshell, theft of ntds.dit, Kerberoasting and deployment of AdaptixC2 through a custom loader capable of patching AMSI and ETW. The stolen data, including records from an energy billing environment, was sold under the masterblack alias and later reused in a phishing and invoice-fraud platform that generated more than 2.4 million messages.
Organisations should update PAN-OS and Prisma Access, disable Authentication Override where unnecessary and hunt for DNS tunnelling, rclone execution and AdaptixC2 artefacts.
Star Blizzard expands phishing campaigns and deploys CosmicPulse through RedFlick
Microsoft attributes at least 13 phishing campaigns conducted during 2026 to Star Blizzard, a Russian state-linked actor associated with FSB Centre 18. The activity affected more than 100 organisations, primarily in the United States and United Kingdom, as well as entities connected to Ukraine.
The group uses fake event invitations, email accounts hosted on compromised WordPress and cPanel sites, and password-protected RAR or ZIP archives. Its new RedFlick technique uses Windows scheduled tasks to deploy the Python-based CosmicPulse backdoor, while other observed chains include LNK files disguised as PDFs, MSI packages, WebDAV and execution through control.exe. Microsoft also notes an evolution from the actor’s previous use of ClickFix.
Defenders should hunt for the scheduled tasks Internet Quality Test Connection, Network Configuration Manager and System Health Monitor, together with detections associated with RedFlick and CosmicPulse.
China-linked UAT-11587 uses Microsoft 365 to control the new Antino backdoor
Cisco Talos has identified activity linked to UAT-11587, a group it assesses with high confidence to have ties to China and that targets government, diplomatic, academic and security organisations across several Asian countries. The campaign uses highly tailored spear-phishing emails to deploy Antino, a Rust-based backdoor that relies on Microsoft Graph, Outlook and OneDrive for command-and-control communications.
This approach allows malicious traffic to blend into legitimate Microsoft 365 activity, making detection more difficult for defenders. Antino provides reconnaissance, command execution, file transfer, persistence and in-memory shellcode-loading capabilities, positioning it as an advanced platform for cyberespionage operations.
◾ This newsletter is one of the deliverables of our Operational and Strategic Intelligence service. If you are interested in knowing the rest of the Operational and Strategic Intelligence contents included in the service, please contact us →
Cloud & Business Apps
Cybersecurity
Data & AI
IoT & Connectivity
Industry
Health
Banking and Finance
Public Sector
Retail
Tourism and Leisure
Transport & Logistics
Energy & Utilities
Smart Cities