logo

Oracle PeopleSoft breaches widen; malicious Chrome extension steals searches; Mustang Panda targets India

ID: 5b6dea6a-ad33-53ad-a55c-a3439c2eb4ea

STIX ID: report--5b6dea6a-ad33-53ad-a55c-a3439c2eb4ea

Feed Name: defend.network

Threat Score
86/100

Date Published: 2026-06-30

Date Updated: 2026-07-02

Author: defend.network

...
...

This briefing reports multiple high-risk active threats: an Oracle PeopleSoft zero-day exploited by ShinyHunters to steal employee/configuration data from Nissan and NAIC, a malicious Chrome extension impersonating Perplexity AI that logged searches and address-bar input, Mustang Panda using Zoho WorkDrive as a command channel against Indian government and hydropower targets, and a SimpleHelp authentication bypass (CVE-2026-48558) used to deploy the Djinn infostealer; it provides urgent remediation and detection actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.