More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
ShinyHunters hit the University of Nottingham’s PeopleSoft instance with a zero-day gadget chain, siphoning off 40 GB of data on 454,600 students. Stolen fields include passport numbers, billing records, addresses and disability details. Universities running Oracle PeopleSoft should check PSAPPSRV.LOG and PS_HOME/appserv logs for unusual SQL pulls, confirm they’re on the latest patch, lock down admin accounts behind MFA and IP allow-lists. In a separate incident, Kyushu Electric Power lost an external backup drive containing names, addresses, electricity usage and phone numbers for 10.9 million customers. That lapse highlights how a simple physical-security gap can expose massive data sets.
On the vulnerability front, InfoGuard’s “Ghost-Sender” exploit lets attackers spoof any Exchange Online or hybrid address—including CEO or noreply—by flipping a one-line PowerShell script. It bypasses SPF, DKIM and DMARC, so defenders need to disable Direct Send or enforce connector-based IP and certificate checks. At GitHub, a new toolkit called Miasma turns commits into C2 channels, pushing encrypted payloads through orphaned Actions and tainting AI coding-tool configs. Hunt for its three commit search strings (“DontRevokeOrItGoesBoom,” “TheBeautifulSandsOfTime,” “firedalazer”), lock down OIDC token scopes, and revoke any suspect PATs. Meanwhile, a researcher netted over \$500,000 in bounties by scraping thousands of Google API keys with an AI-driven fuzzer and probing for internal-only endpoints that leaked sensitive account and configuration data. Those findings suggest you need tighter rate limits, improved key management and anomaly detection on API usage.
Questions about this article
No questions yet.