// 4 ZERO-DAY · 6 CVE · 10 EXPLOIT · 1 ADVISORY IN THE LAST 24H→
SENT ISSUE WEEKLY-2026-W40

DeafLetter — week 40

ShinyHunters Hits the FBI: PeopleSoft Zero-Day and a Vacuum of Confirmation

SNAPSHOT // IMMUTABLEEN
DEAFNEWS DEAFLETTER // SECURITY BRIEF
VERIFIED SIGNALS // EDITORIAL SNAPSHOT

DeafLetter — week 40

ShinyHunters Hits the FBI: PeopleSoft Zero-Day and a Vacuum of Confirmation

01 // LEAD STORY
LEAD // 01

ShinyHunters Hits the FBI: PeopleSoft Zero-Day and a Vacuum of Confirmation

The criminal group claims it breached the FBI by exploiting a zero-day in Oracle PeopleSoft. No confirmation has come from the FBI, Oracle, or security vendors, leaving the industry paralyzed between immediate alarm and legitimate skepticism.

OPEN REPORT →
02 // THREE SIGNALS
SIGNAL // 02

CISA Adds Two Actively Exploited Flaws to KEV Catalog: SharePoint and MikroTik

On September 25, 2026, CISA added CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint Server (CVSS 8.8), and CVE-2026-67279, an SSH authentication bypass in MikroTik RouterOS (CVSS 6.9), to its Known Exploited Vulnerabilities Catalog. Federal Civilian Executive Branch agencies must apply patches by September 28, 2026. While the deadline is not binding for private organizations, confirmed exploitation and functional attack chains make urgent risk assessment essential.

READ THE ANALYSIS →
SIGNAL // 03

Meta Muse macOS: Local Bug Hijacks Dictation to Malicious Servers

Patrick Wardle has disclosed a zero-day vulnerability in Meta Muse for macOS. The endo_voyager_dictation_endpoint setting can be modified by unprivileged local processes, redirecting dictation traffic to attacker-controlled endpoints.

READ THE ANALYSIS →
SIGNAL // 04

Kiteworks Orders Server Shutdown After Federal Intelligence Warns of Imminent Attack

Kiteworks instructed customers to power down servers for six hours following credible threat intelligence from federal authorities. No breach has been confirmed, and the vendor has not identified a specific vulnerability or CVE. The measure is strictly preventative.

READ THE ANALYSIS →
03 // CVES AND PATCHES
CVE_PATCH // 05

MedImpact Data Breach: 11 Months of Silence and the Shadow of Qilin

MedImpact Healthcare Systems took 11 months to notify individual members after a data breach attributed to the Qilin ransomware group. Edelson Lechtzin LLP is investigating a potential class action.

READ THE ANALYSIS →
CVE_PATCH // 06

D-Link Already Declared EOL for DIR-895L; CVE-2026-100740 Gets No Patch

CVE-2026-100740 hits D-Link DIR-895L routers with a CVSS 9.9 score. The vendor declared the series End-of-Life in 2019, ruling out any firmware updates.

READ THE ANALYSIS →
CVE_PATCH // 07

WordPress Under Attack: Malicious PHP Files in /tmp in Under Five Hours

CVE-2026-87902 is being actively exploited to write malicious files to WordPress servers. Upgrading to 7.1.2 does not remove compromises that have already occurred.

READ THE ANALYSIS →
CVE_PATCH // 08

FBIJobs Breach: Recruitment Databases Are Prime Intelligence Assets

The FBI confirmed on September 20, 2026, that it is investigating a cyber incident involving its FBIJobs.gov recruitment portal. The ShinyHunters group claimed responsibility, asserting a broader compromise than the agency acknowledged, including the theft of "vast amounts of data." The FBI stated it remains unclear whether the breach originated in an internal system or at a third-party vendor. This analysis frames the incident as a strategic warning: recruitment databases hold human maps that, if compromised, expose national intelligence risks.

READ THE ANALYSIS →
CVE_PATCH // 09

CVE-2026-85102: Three Days from Patch to Exploit on Check Point VPN

Check Point confirms active attacks against CVE-2026-85102 starting September 12, 2026, three days after patches were released. CISA sets a federal deadline of September 25.

READ THE ANALYSIS →
04 // THE GUIDE
GUIDE // 10

Foundations of Ethical Security Testing with Python: A Beginner's Laboratory Guide

You have a terminal open and a fresh Kali ISO on your desktop, but no idea which command runs first—or whether that command is even legal. This guide is for that exact moment. We start from zero: installing Python, writing your first script, and understanding why a variable named `password` is not the same as a variable named `PASSWORD`. From there we build a vocabulary of defense—CIA triad, CVE, scope, responsible disclosure—and construct a legally isolated lab network we call Wintermute. Every attack category is taught from two angles: how it works conceptually, and how you would detect or block it. You will not find live exploit code against real targets here. You will find commented Python snippets, lab checklists, and the explicit requirement of written authorization before any technique leaves your virtual network. Sections 1–4 establish your toolkit and ground rules; Sections 5–9 walk network reconnaissance, web application flaws, DoS concepts, wireless and social vectors, and malware mechanics without executing dangerous payloads; Sections 10–11 consolidate everything into a capstone assessment and a troubleshooting reference for when your lab inevitably breaks. Read with a notebook, test only in machines you own, and treat every script as a defensive sensor in disguise. **What you need:** a laptop with 8 GB RAM, VirtualBox or VMware, and patience for your first syntax errors. **What you will not do:** run unmodified exploits against infrastructure you do not own.

READ THE ANALYSIS →
MANAGE PREFERENCES →
You receive this email because you subscribed to DeafLetter. Unsubscribe
Samuel — DeafNews · Privacy