Threats & Adversaries · Web App Attack
Huntress Maps Webshells Across Shared Member Accounts Huntress said attackers are using member accounts on a shared recreation-management platform to plant webshells across three municipal servers, and Dutch police separately arrested 24-year-old Pepijn van der Stap in a ShinyHunters probe tied to CVE-2026-35273 . The attack has been active for nine days and moved from noisy probing to repeatable file-upload abuse.
The trick is simple: a normal member signs up, uploads a file the server will execute, and the upload turns into code running on the web server instead of a harmless attachment. Because the platform shares upload handling and storage across tenants, the attacker can use that foothold to browse into other tenants’ folders, probe payment data, and even come back after a server cleanup if isolation is still weak.
For operators of shared web apps, the lasting issue is not one compromised account but a trust model that lets low-privilege uploads cross tenant lines. If tenant boundaries and web execution paths overlap, a member login can become a persistent foothold that outlives a single server rebuild or account lockout.
14 sources · Oct 1
NVD KEV
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Known ransomware campaign use. EPSS 9% (95th percentile).
CISA federal remediation date Jun 15 · date passed
Timeline Sources Oct 1 Huntress Blog
Determined Attacker Uploads Malicious Webshells to Parks and Rec Management Platform Servers | Huntress
Huntress SOC found a threat actor exploiting a file upload flaw in recreation management to breach 3 municipal servers and steal payment data.
original Sep 30 Risky Biz News
ShinyHunters suspect arrested in the Netherlands
A ShinyHunters suspect has been arrested in the Netherlands, Apple fixes an iOS zero-day found by Meta, recent Citrix zero-days see mass e [Read More
original Sep 29 SecurityWeek
Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation
Pepijn van der Stap was convicted in 2023 for hacking multiple organizations, stealing their data, and extorting them.
original Part of the PlainSec briefing for 2026-09-24
Every edition of this story: Huntress Maps Webshells Across Shared Member Accounts
More from today
Threats & Adversaries · Web App Attack
Huntress Maps Webshells Across Shared Member Accounts Huntress said attackers are using member accounts on a shared recreation-management platform to plant webshells across three municipal servers, and Dutch police separately arrested 24-year-old Pepijn van der Stap in a ShinyHunters probe tied to CVE-2026-35273 . The attack has been active for nine days and moved from noisy probing to repeatable file-upload abuse.
The trick is simple: a normal member signs up, uploads a file the server will execute, and the upload turns into code running on the web server instead of a harmless attachment. Because the platform shares upload handling and storage across tenants, the attacker can use that foothold to browse into other tenants’ folders, probe payment data, and even come back after a server cleanup if isolation is still weak.
For operators of shared web apps, the lasting issue is not one compromised account but a trust model that lets low-privilege uploads cross tenant lines. If tenant boundaries and web execution paths overlap, a member login can become a persistent foothold that outlives a single server rebuild or account lockout.
14 sources · Oct 1
NVD KEV
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Known ransomware campaign use. EPSS 9% (95th percentile).
CISA federal remediation date Jun 15 · date passed
Timeline Sources Oct 1 Huntress Blog
Determined Attacker Uploads Malicious Webshells to Parks and Rec Management Platform Servers | Huntress
Huntress SOC found a threat actor exploiting a file upload flaw in recreation management to breach 3 municipal servers and steal payment data.
original Sep 30 Risky Biz News
ShinyHunters suspect arrested in the Netherlands
A ShinyHunters suspect has been arrested in the Netherlands, Apple fixes an iOS zero-day found by Meta, recent Citrix zero-days see mass e [Read More
original Sep 29 SecurityWeek
Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation
Pepijn van der Stap was convicted in 2023 for hacking multiple organizations, stealing their data, and extorting them.
original Part of the PlainSec briefing for 2026-09-24
Every edition of this story: Huntress Maps Webshells Across Shared Member Accounts
More from today