Cybersecurity Headlines β September 27, 2026
- ShinyHunters hackers expanded attacks on Oracle’s PeopleSoft, Google says β CNA
- Chinaβs grand strategy, and what Nepal must understand β Khabarhub.com
- Bitget pauses withdrawals after $387.5M hack, CEO assures funds safe β Crypto Briefing
- Trump frames unregulated AI as a way to keep ahead of China β but in fact, it harms US national security β The Conversation Africa
- CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks β BleepingComputer
- Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack | TechCrunch β TechCrunch
- In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure β Securityweek.com
- CISA Unveils Election Security Plan Ahead of 2026 Midterms β Infosecurity Magazine
- Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild β Internet
- 8 insights from Proofpoint Protect: Security bets on intent as AI agents join the workforce β SiliconANGLE News
From the Trenches
As a cybersecurity practitioner, I’ve been keeping an eye on some concerning developments that warrant attention from anyone handling sensitive data or systems. One of the most interesting and actionable stories to me is the expansion of ShinyHunters’ attacks on Oracle’s PeopleSoft by Google. This group has already shown themselves to be quite skilled at breaching enterprise software, and now they’re going after another major player in the industry. The implications for organizations that use PeopleSoft are clear: if these hackers can get in, they’ll likely find a way out.
Another story that caught my eye is Bitget’s pause on withdrawals following a $387.5 million hack. While this might seem like an isolated incident to some, it highlights the growing importance of robust security measures in cryptocurrency exchanges. The fact that the CEO assured funds were safe suggests that the exchange had adequate insurance coverage, but I’d argue that this shouldn’t be the case. Any reputable exchange should prioritize security over profits.
In both cases, what’s clear is that organizations and individuals need to take a proactive approach to cybersecurity. The threat landscape is constantly evolving, and we can’t afford to wait for incidents like these to happen before taking action. By staying informed and investing in robust security measures, we can reduce the risk of falling victim to attacks.
π§ Patch Priority: Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
Compiled daily. Stay patched, stay vigilant.