In partnership with

~6 MIN READ
FACT Mandiant dates UNC6240's original exploitation of Oracle PeopleSoft CVE-2026-35273 to May 27 through June 9, 2026; Oracle's advisory did not land until June 10, meaning attackers had roughly two weeks of free run on a CVSS 9.8 bug before defenders even knew it existed. (The Hacker News / Mandiant, June 2026)
The Signal
 
Attackers are weaponizing AI at every level this week: autonomous retail skimmers, poisoned enterprise AI agents, and zero-days rebuilt on the fly to sidestep fresh defenses. The infrastructure is getting smarter. Is yours?

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe →

In this edition
  📌 Big Cyber News
  🚨 Can't Miss
  🤖 AI in Cyber
  🕵️ Threat Intel
  🛠️ Tools & Tactics
  🧪 Strange Cyber
📌 Big Cyber News
 
Exploit Bypass
Defenders Blocked the Oracle PeopleSoft Exploit. So Attackers Rebuilt It.
Intro
UNC6240, the threat actor Mandiant links to ShinyHunters, got blocked by enterprise defenders. So they rewrote the exploit and came back.
What Happened
The group had been exploiting CVE-2026-35273 (CVSS 9.8) in Oracle PeopleSoft since June. When defenders deployed WAF rules to block the PSEMHUB endpoint, UNC6240 modified its exploit to bypass them. Web shells are now confirmed on dozens of systems across multiple sectors, with the Neo-reGeorg tunneling toolkit and MeshAgent RMM software deployed for persistent access.
Why It Matters
When a threat actor rewrites its exploit specifically to sidestep your defenses, your WAF just became a data point in their next attack. Mid-campaign retooling separates persistent threats from opportunistic ones, and UNC6240 is firmly in the first category.
The Other Side
Oracle has issued patches and guidance, and no widespread confirmed data theft has been publicly reported. Organizations that patched in June and restricted PSEMHUB externally from the start have limited exposure.
 
👉 Takeaway
Block external access to the PSEMHUB endpoint now, verify your June patches are applied, and audit your environment for MeshAgent artifacts you did not install.
TL;DR: UNC6240 bypassed WAF rules blocking a CVSS 9.8 Oracle PeopleSoft exploit by rewriting the exploit itself.
Further reading: The Hacker News
🚨 Can't Miss
 
 
Vulnerability/RCE
A directory traversal flaw (CVE-2026-93616, CVSS 9.8) lets unauthenticated attackers execute remote code across Check Point's entire management product line: Security Management, Multi-Domain, Log Server, and SmartEvent. CISA added it to the KEV catalog. Patch is R82.20; interim mitigation is restricting TCP port 19009 to trusted IPs. The product that protects your network has an unauthenticated RCE in its own management console.
→ Apply the R82.20 hotfix today, or lock port 19009 to trusted IPs until you can.
 
Platform Alert
Kiteworks (formerly Accellion) told customers to stop using its platform based on credible threat intelligence from federal authorities. No confirmed compromise, but the precautionary shutdown points to a potential zero-day situation. Clop zero-day'd Accellion's FTA product in December 2020 and hit dozens of organizations. That history makes this warning more credible, not less.
→ If you use Kiteworks, follow its hardening guidance immediately and monitor for indicators of compromise.
 
Misconfiguration
UpGuard found about 16,000 Supabase databases open to the public internet, leaking adult streaming site conversations, U.S. valet service license plates, and immigration contact info. This is not a platform flaw. It is a shared-responsibility failure fueled by AI-generated apps shipped without security review. Supabase calls it "secure by default." Sixteen thousand exposed databases call it something else.
→ Verify your Supabase Row-Level Security settings are enabled and no tables are publicly readable.

Analytics on Live Data Without Leaving Postgres

When analytics on Postgres slows down, most teams add a second database. Then come the pipelines, the sync jobs, and a copy of your data that's always a little behind.

TimescaleDB takes a different approach: extend Postgres instead of splitting away from it. Hypertables partition your data automatically as volume grows. Hypercore compression cuts storage up to 95%. Continuous aggregates keep dashboards live without re-querying everything.

CERN runs Postgres this way for sensor data from the Large Hadron Collider.

No split architecture, no pipeline lag, no new query language to learn. Same SQL, same drivers, same tools.

Start on Tiger Cloud and get $1000 in credits.

🤖 AI in Cyber
 
 
AI Attack
Researchers at Gambit found a three-stage AI toolchain (Strix for vulnerability hunting, Cairn for autonomous pentesting, Hermes on claude-opus-4.6 for orchestration and intrusions) that launched 105 attack projects against online retailers between September 10 and 15, with a human operator typing short prompts in Chinese while the AI handled the rest. Mean cost per scan: about $25. Haul from just two breached retailers: over 600,000 credit cards. This is a production pipeline, not a proof of concept.
→ Audit your checkout flows and payment integrations for card-skimming script injections.
 
AI Attack Surface
Researchers found three "SalesBleed" flaws in Salesforce Agentforce. Attackers embed malicious instructions in Web-to-Lead form submissions; those stay dormant until Agentforce processes them, then silently exfiltrate CRM data while reporting "content blocked." A third flaw weaponized the Agentforce-Slack integration to send phishing messages from what appeared to be trusted internal sources. All three patched August 19.
→ Confirm you are on the patched version and audit your Agentforce-Slack integration permissions.
🕵️ Threat Intel
 
 
Nation-State Exploit Chain
UTA0565 chained two Chrome zero-days (CVE-2026-85046, CVE-2026-87491) with a Windows sandbox escape (CVE-2026-85880) to deliver CLEANGULP malware via phishing emails impersonating the Center for American Progress. Lure sites mimicked legitimate news outlets with near-identical domain names. Multiple Chinese cyber-espionage groups have since been observed sharing the same exploit kit.
→ Keep Chrome updated and train staff to verify domain spelling before clicking links in news-impersonating emails.
 
Credential Attack
Attackers call targets posing as IT help desk staff and send an SMS to a fake sign-in page using adversary-in-the-middle or device-code auth flows to harvest passkeys and session tokens. Post-access: Microsoft Graph API recon, then bulk downloads of SharePoint, OneDrive, and Exchange data from separate exfil infrastructure. Watch for domains like passkeyhelpdesk[.]com or [orgname].[suspiciousdomain] patterns.
→ Train help desk staff that outbound calls triggering sign-in requests are a red flag, and monitor for unexpected Graph API activity.
🛠️ Tools & Tactics
 
 
Deception
CISA published its first guide dedicated entirely to cyber deception: honeytokens, fake credentials, and network tripwires designed to catch attackers using legitimate tools to avoid detection. The guide maps to MITRE ATT&CK and the ENGAGE framework and pairs with Zero Trust architectures. The core play: place fake credentials where legitimate users would never touch them, so any access triggers an immediate alert.
→ Start with a fake admin account in Active Directory or a honeytoken in an S3 bucket policy, then build from there.

Parallel, Turbopuffer, and Wordsmith run their entire GTM motion on Attio, with agents that chase every buying signal, build pipeline, and move deals forward, 24/7. Try Attio now.

🧪 Strange Cyber
 
Strange but real
The Army Sentenced This Soldier to 70 Months for Hacking. Then He Tried to Get AI to Help Him Hack From Jail.
Intro
Cameron Wagenius was 22, stationed in South Korea, and had already stolen call and text records for more than 100 million AT&T customers. Getting arrested did not fully slow him down.
What Happened
Wagenius (online handle: Kiberphant0m) pleaded guilty to stealing and extorting telecom customer data pulled from poorly secured Snowflake accounts. While incarcerated and awaiting sentencing, he used a fellow inmate's email account to ask the recipient to prompt a commercial AI tool for Windows 10 privilege escalation and bypass techniques, a textbook attempt to talk the AI past its guardrails. The federal judge sentenced him to 70 months and $300,000 in restitution.
Why It Matters
The takeaway is not that soldiers hack. It is that AI tools available to any subscriber are now the first thing a motivated bad actor reaches for, even from a federal detention facility with restricted computer access. The attack surface runs all the way to the jail cell.
The Other Side
Wagenius was cooperative with investigators, which the court noted. He was not a state-sponsored operation. He was a 22-year-old who found that breach data was lucrative and kept poking at systems long past any reasonable stopping point.
 
👉 Takeaway
If someone will try to jailbreak a commercial AI by proxy from a jail cell, your threat model for anyone with unrestricted internet access should be set higher than you might assume.
TL;DR: A jailed soldier used another inmate's email to get an AI asked how to escalate Windows privileges. He got 70 months to reconsider.
Further reading: Krebs on Security

Found the right hire, but no entity in their country? Remote becomes the legal employer — handling contracts, benefits, tax setup, and onboarding, with most hires started in under 3 days. See how it works.