ShinyHunters Hits Global Firms as Oracle PeopleSoft Exploit Spreads
Planck

- ShinyHunters bypasses new web defenses to exploit critical CVE-2026-35273 flaw
- Multiple sectors compromised, with attackers claiming FBI personnel data theft
On September 26, 2026 (UTC), CoinDesk reported that hackers from the ShinyHunters group initiated a mass exploitation campaign targeting Oracle PeopleSoft systems worldwide. Many organizations failed to apply Oracle’s official patch, which was released on June 10, 2026. According to Google’s Mandiant unit, the campaign began between May 27 and June 9 and rapidly escalated as attackers adapted methods to bypass web application firewall (WAF) rules and focus on unpatched systems. As a result, organizations across higher education, technology, healthcare, government, and other sectors were compromised.
On September 25, 2026, Reuters reported that ShinyHunters resumed attacks by exploiting the critical PeopleSoft vulnerability CVE-2026-35273. This vulnerability facilitates unauthenticated remote code execution via the `/PSEMHUB/` endpoint in the Environment Management Hub. After many organizations deployed WAF body-inspection rules to block initial exploit attempts, ShinyHunters adjusted its tactics and targeted systems that had these defenses in place but lacked Oracle’s patch, effectively bypassing WAF signatures and maintaining access.
According to Mandiant, ShinyHunters deployed persistent web shells across dozens of compromised systems globally, and these web shells granted continued access for further malicious activity. Affected industries include universities, technology firms, healthcare organizations, agricultural and transportation providers, and government entities. On September 23, 2026, Reuters reported that ShinyHunters claimed to have used the vulnerability to steal sensitive Federal Bureau of Investigation personnel records, including names, unit affiliations, and confidential medical or psychiatric data. The FBI announced an active investigation into the breach as of that date. Although Reuters could not independently verify these claims, leaked materials appear to contain internal FBI information.
This campaign’s technical escalation distinguishes it from earlier attacks, as organization-level WAF and firewall rules proved insufficient against unpatched software. Attackers successfully evaded filtering strategies and exploited the core vulnerability. Oracle has not issued further comment beyond its earlier out-of-band security advisory and patch notice, and Mandiant emphasized that full patching of all PeopleSoft instances remains critical because unaddressed vulnerabilities continue to leave systems exposed to significant risk.
Recent market research and incident data indicate that ShinyHunters’ campaign persists across sectors, and investigators observed web shells on numerous compromised systems. Therefore, the attack continues wherever Oracle’s official patch remains unapplied or insecure endpoints are accessible, underscoring the urgent need for rapid remediation.
Get the latest news in your inbox!





