Oracle PeopleSoft breaches widen; malicious Chrome extension steals searches; Mustang Panda targets India
ID: 5b6dea6a-ad33-53ad-a55c-a3439c2eb4ea
STIX ID: report--5b6dea6a-ad33-53ad-a55c-a3439c2eb4ea
Feed Name: defend.network
This briefing reports multiple high-risk active threats: an Oracle PeopleSoft zero-day exploited by ShinyHunters to steal employee/configuration data from Nissan and NAIC, a malicious Chrome extension impersonating Perplexity AI that logged searches and address-bar input, Mustang Panda using Zoho WorkDrive as a command channel against Indian government and hydropower targets, and a SimpleHelp authentication bypass (CVE-2026-48558) used to deploy the Djinn infostealer; it provides urgent remediation and detection actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
