Federal authorities and major enterprise platforms are responding to a widespread cybersecurity escalation involving active exploitation of the Oracle PeopleSoft vulnerability CVE-2026-35273 and emergency shutdowns ordered for Kiteworks and Citrix NetScaler instances. The threat actor group ShinyHunters, identified by Mandiant and the Google Threat Intelligence Group as UNC6240, has deployed a backdoor named SIDEEYE across multiple sectors using a critical flaw that bypasses web application firewalls.
Oracle PeopleSoft Vulnerability and FBI Breach
The cybercriminal group ShinyHunters has been actively exploiting CVE-2026-35273, a critical Oracle PeopleSoft security flaw carrying a CVSS score of 9.8 that was initially patched in June 2026. According to details compiled by Google, the campaign successfully evades web application firewalls and has expanded from universities into the healthcare, public, technology, and transportation sectors. On September 25, 2026, server breaches linked to this campaign affected the FBI, exposing personal information belonging to bureau employees and applicants. Reports published by The Register indicate that the attackers used unpatched PeopleSoft architecture that had remained unupdated since the June patch release. Concurrently, public disclosures and threat intelligence trackers noted that ShinyHunters infiltrated the rival ransomware operation Cl0p, defacing its darknet infrastructure.
Kiteworks Emergency Shutdown Orders
Organizations utilizing the Kiteworks secure file-sharing platform faced emergency operational halts following credible threat intelligence reports. According to platform communications cited by The Hacker News, Kiteworks warned customers that federal intelligence authorities detected potential targeting of its systems by a threat actor. The company advised administrators to initiate a multi-hour system shutdown on September 26, 2026, while stating that no internal compromise had been detected. Kiteworks urged all users to upgrade immediately to version 9.5.1, which addresses known vulnerabilities. Administrator.de records show the platform is deployed across multiple state banks, insurance providers, media enterprises, consulting firms, and automotive suppliers.
https://x.com/IntCyberDigest/status/2103864155493056635
Citrix NetScaler Zero-Day Warnings
System administrators received urgent directives from IT vendors to deactivate Citrix NetScaler instances following reports of a previously unknown, actively exploited zero-day vulnerability. Independent reports and Reddit discussions highlighted by system administrators pointed to the emergence of new Common Vulnerabilities and Exposures (CVEs) facilitating remote code execution. Lacking official software patches prior to the weekend, organizations across various sectors opted to take their NetScaler gateways offline to mitigate potential unauthorized access while awaiting official remediation guidance from Citrix.

Incident Overview
| Platform / Vendor | Primary Threat Vector | Impacted Sectors | Mitigation Action |
|---|---|---|---|
| Oracle PeopleSoft | CVE-2026-35273 (WAF bypass, CVSS 9.8) | FBI, healthcare, public sector, tech, transport | Apply June 2026 patch, remove SIDEEYE backdoor |
| Kiteworks | Credible threat intelligence warning | State banks, insurers, media, automotive suppliers | Upgrade to version 9.5.1, temporary system shutdown |
| Citrix NetScaler | Active zero-day remote code execution exploits | Government agencies, enterprise organizations | Immediate instance deactivation pending patches |
Frequently Asked Questions
What caused the FBI data breach in September 2026?
According to security findings from Mandiant and Google Threat Intelligence, the breach utilized the Oracle PeopleSoft vulnerability CVE-2026-35273, which bypassed web application firewalls on unpatched servers.
https://x.com/DarkWebInformer/status/2103631790841929823
Why were Kiteworks systems shut down on September 26, 2026?
Kiteworks issued an emergency shutdown recommendation after receiving credible threat intelligence from federal authorities warning of potential targeting by malicious actors.
What remediation steps are available for the Citrix NetScaler issue?
System administrators were advised by IT security teams to temporarily deactivate their NetScaler instances and await official software patches addressing the newly identified remote code execution vulnerabilities.
Worth a look