| ~6 MIN READ |
|
Attackers are weaponizing AI at every level this week: autonomous retail skimmers, poisoned enterprise AI agents, and zero-days rebuilt on the fly to sidestep fresh defenses. The infrastructure is getting smarter. Is yours?
PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe → |
|
In this edition
|
Exploit Bypass
Defenders Blocked the Oracle PeopleSoft Exploit. So Attackers Rebuilt It.
Intro
UNC6240, the threat actor Mandiant links to ShinyHunters, got blocked by enterprise defenders. So they rewrote the exploit and came back.
What Happened
The group had been exploiting CVE-2026-35273 (CVSS 9.8) in Oracle PeopleSoft since June. When defenders deployed WAF rules to block the PSEMHUB endpoint, UNC6240 modified its exploit to bypass them. Web shells are now confirmed on dozens of systems across multiple sectors, with the Neo-reGeorg tunneling toolkit and MeshAgent RMM software deployed for persistent access.
Why It Matters
When a threat actor rewrites its exploit specifically to sidestep your defenses, your WAF just became a data point in their next attack. Mid-campaign retooling separates persistent threats from opportunistic ones, and UNC6240 is firmly in the first category.
The Other Side
Oracle has issued patches and guidance, and no widespread confirmed data theft has been publicly reported. Organizations that patched in June and restricted PSEMHUB externally from the start have limited exposure.
TL;DR: UNC6240 bypassed WAF rules blocking a CVSS 9.8 Oracle PeopleSoft exploit by rewriting the exploit itself.
Further reading: The Hacker News
|
|
Analytics on Live Data Without Leaving Postgres
When analytics on Postgres slows down, most teams add a second database. Then come the pipelines, the sync jobs, and a copy of your data that's always a little behind.
TimescaleDB takes a different approach: extend Postgres instead of splitting away from it. Hypertables partition your data automatically as volume grows. Hypercore compression cuts storage up to 95%. Continuous aggregates keep dashboards live without re-querying everything.
CERN runs Postgres this way for sensor data from the Large Hadron Collider.
No split architecture, no pipeline lag, no new query language to learn. Same SQL, same drivers, same tools.
Start on Tiger Cloud and get $1000 in credits.
|
|
|
Parallel, Turbopuffer, and Wordsmith run their entire GTM motion on Attio, with agents that chase every buying signal, build pipeline, and move deals forward, 24/7. Try Attio now.
Strange but real
The Army Sentenced This Soldier to 70 Months for Hacking. Then He Tried to Get AI to Help Him Hack From Jail.
Intro
Cameron Wagenius was 22, stationed in South Korea, and had already stolen call and text records for more than 100 million AT&T customers. Getting arrested did not fully slow him down.
What Happened
Wagenius (online handle: Kiberphant0m) pleaded guilty to stealing and extorting telecom customer data pulled from poorly secured Snowflake accounts. While incarcerated and awaiting sentencing, he used a fellow inmate's email account to ask the recipient to prompt a commercial AI tool for Windows 10 privilege escalation and bypass techniques, a textbook attempt to talk the AI past its guardrails. The federal judge sentenced him to 70 months and $300,000 in restitution.
Why It Matters
The takeaway is not that soldiers hack. It is that AI tools available to any subscriber are now the first thing a motivated bad actor reaches for, even from a federal detention facility with restricted computer access. The attack surface runs all the way to the jail cell.
The Other Side
Wagenius was cooperative with investigators, which the court noted. He was not a state-sponsored operation. He was a 22-year-old who found that breach data was lucrative and kept poking at systems long past any reasonable stopping point.
TL;DR: A jailed soldier used another inmate's email to get an AI asked how to escalate Windows privileges. He got 70 months to reconsider.
Further reading: Krebs on Security
|
Found the right hire, but no entity in their country? Remote becomes the legal employer — handling contracts, benefits, tax setup, and onboarding, with most hires started in under 3 days. See how it works.


