Huntress Maps Webshells Across Shared Member Accounts
Huntress said attackers are using member accounts on a shared recreation-management platform to plant webshells across three municipal servers, and Dutch police separately arrested 24-year-old Pepijn van der Stap in a ShinyHunters probe tied to CVE-2026-35273. The attack has been active for nine days and moved from noisy probing to repeatable file-upload abuse.
The trick is simple: a normal member signs up, uploads a file the server will execute, and the upload turns into code running on the web server instead of a harmless attachment. Because the platform shares upload handling and storage across tenants, the attacker can use that foothold to browse into other tenants’ folders, probe payment data, and even come back after a server cleanup if isolation is still weak.
For operators of shared web apps, the lasting issue is not one compromised account but a trust model that lets low-privilege uploads cross tenant lines. If tenant boundaries and web execution paths overlap, a member login can become a persistent foothold that outlives a single server rebuild or account lockout.
A vulnerability in a popular line of products from Oracle is being used in a new campaign by the prolific ShinyHunters hacking group, which recently claimed credit for an attack on the FBI’s jobs site.
Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group.
Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters.
Cybercrime experts are stunned as ShinyHunters risks agent safety and intense federal heat in a bizarre attempt to force the retraction of an agency advisory.
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.