Top news stories this week
- PeopleSoft touch. ShinyHunters claim FBI breach amid renewed PeopleSoft attacks
- Patch priority. Critical flaws hit TeamViewer, Citrix, Fortinet, Cisco and Kiteworks
- Mind the security gap. Japanese rail firms disclose online security breaches
- Vibekiller. Misconfigured Supabase databases expose thousands of AI-built applications
- Phoney executives. AI-enabled impersonation drives payment fraud
- Delayed discovery. Pentagon compromised by months-long data breach
1. PeopleSoft exploitation campaign linked to FBI breach as ShinyHunters affiliate arrested
ShinyHunters has resumed mass exploitation of Oracle PeopleSoft vulnerability CVE-2026-35273 and claims to have used the flaw, alongside a previously unknown vulnerability, to compromise the FBI Jobs platform. While the FBI is still assessing the full impact of the incident, the breach is particularly concerning because the stolen data reportedly includes sensitive personal information that could expose personnel working in high-risk investigative and intelligence roles.
Separately, Dutch authorities have arrested a previously convicted cybercriminal suspected of ties to ShinyHunters.
So what?
ShinyHunters' ability to bypass the vulnerability mitigations demonstrates how quickly threat actors can adapt their tradecraft to continue targeting high-value environments. However, high-profile attacks are likely to attract significant attention of the law enforcement leading to the disruption of their criminal activities.
[Researcher: Milda Petraityte]
2. Critical flaws hit TeamViewer, Citrix, Fortinet, Cisco and Kiteworks
Recent disclosures affecting TeamViewer, Kiteworks, Citrix NetScaler, Fortinet and Cisco SD-WAN highlight elevated risks across remote access, file transfer, VPN, and network management infrastructure. Citrix, Fortinet and Cisco have reported that their respective vulnerabilities are being actively exploited. TeamViewer has disclosed five high severity flaws, while Kiteworks has taken the unusual step of encouraging customers to temporarily shut down systems following credible threat intelligence.
So what?
Organisations must work to identify vulnerable deployments of the tools listed and patch or isolate affected systems as soon as possible. Where exploitation is suspected or confirmed, organisations are highly encouraged to engage incident response specialists.
[Researcher: Steve Ross]
3. Japanese rail firms disclose online security breaches
Two rail operators in Tokyo reported breaches of their online systems in the same week. Tokyo Metro disclosed that unauthorised access from overseas may have resulted in 59,000 email addresses of its loyalty program members being leaked. Separately, Keio Corporation reported that a ransomware attack had disabled portions of its sales system. Both companies emphasised that at no point had their train services been impacted.
So what?
Critical infrastructure operators such as railway firms should validate rather than assume separation between online services, corporate IT and operational environments. Companies should regularly test operational continuity and dependencies.
[Researcher: Lester Lim]
4. Misconfigured Supabase databases expose thousands of AI-built applications
More than 16,000 misconfigured Supabase databases have been found exposing sensitive data, including PII, passwords and authentication tokens. The issue has been linked to poor security configurations and comes at a time when Supabase is increasingly used as the default backend for applications built with AI coding tools. AI-assisted development now reportedly accounts for more than 60% of newly created databases.
Separately, Singapore's first reported AI-related data breach exposed more than 95,000 customer email addresses after an AI-generated bulk-email script was deployed.
SO WHAT?
As organisations increasingly rely on AI to build systems and support decisions involving sensitive information, responsibility for validating security controls, scrutinising AI-generated outputs, and understanding the infrastructure entrusted with that data remains with the organisation.
[Researcher: Gabriella Nolan]
5. AI-enabled impersonation drives payment fraud
Private bank Fideuram transferred approximately USD 108 million after scammers used fabricated messages, documents and an AI-cloned voice to impersonate senior executives and a lawyer.
Separately, in Singapore, a healthcare company’s CFO was close to transferring SGD 120,000 after scammers impersonated the firm’s chairman and managing director on Microsoft Teams.
So What?
AI-enabled impersonation is increasing the scale and credibility of payment fraud targeting corporate employees. Organisations should enforce multi-step payment approvals and independently verify unexpected, urgent, or confidential payment instructions through established channels.
[Researcher: Tlhalefo Dikolomela]
6. Pentagon compromised by months-long data breach
The Defense Manpower Data Center (DMDC) disclosed that attackers exploited a vulnerability in a file-sharing system between October 2025 and July 2026, stealing sensitive personnel records belonging to approximately 3 million current and former US service members and staff. The breach reportedly remained undetected months before the vulnerability was identified and patched, with the US Department of Defense stating that there is currently no evidence of malicious use of the stolen data.
Separately, France's tax administration failed to detect the theft of taxpayer data for seven weeks after attackers used stolen employee credentials to access internal systems. French authorities later attributed the incident to weak authentication controls, inadequate network segmentation, and monitoring deficiencies.
SO WHAT?
Organisations should regularly monitor their systems, investigate suspicious activity promptly and deploy security patches in a timely manner to reduce the amount of sensitive information exposed and limit the impact of a breach.
[Researcher: Asya Sonnichsen]
