[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDVFUtJ8gSm2TvD5CaNenoEe76FUVe3wFXiwFuWQnjVA":3},{"article":4,"iocs":59},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"56f5dca8-b026-48f1-8fbf-9dc09bac7d30","Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign","google-warns-of-shinyhunters-fresh-oracle-peoplesoft-campaign-3ba40d","The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273. The post Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign appeared first on SecurityWeek.","Mandiant and Google Threat Intelligence Group warned that ShinyHunters (tracked as UNC6240) has launched a fresh campaign exploiting Oracle PeopleSoft vulnerability CVE-2026-35273 to target over 100 organizations across multiple sectors. The group modified its exploit to bypass web application firewall rules by using URL encoding ('%50' for 'P') to reach the vulnerable Environment Management Hub endpoint. After compromising systems, attackers deploy web shells, the SideEye backdoor, Neo-reGeorg tunneling toolkit, and MeshCentral for persistence, data theft, and lateral movement.","ShinyHunters launches mass-exploitation campaign targeting Oracle PeopleSoft CVE-2026-35273 with modified WAF-bypass","Mandiant and Google Threat Intelligence Group (GTIG) over the weekend warned that the notorious extortion group ShinyHunters has launched a fresh mass-exploitation campaign targeting Oracle PeopleSoft customers. An integrated enterprise resource planning (ERP) software suite, PeopleSoft is used across numerous large enterprises for the management of core business functions, including finance, HR, payroll, and supply chain. Google’s warning comes four months after the hacking group was seen exploiting a zero-day vulnerability in PeopleSoft, tracked as CVE-2026-35273, to gain remote code execution without authentication. ShinyHunters, tracked by Google as UNC6240, targeted more than 100 PeopleSoft customers in June. Confirmed victims include the University of Nottingham in the UK, insurance regulators group NAIC, and Nissan. “This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint,” Mandiant and GTIG warn now. In the recent attack aimed at the FBI, ShinyHunters claimed to have leveraged a PeopleSoft zero-day. The hackers may be referring to this modified exploit rather than a new zero-day. Advertisement. Scroll to continue reading. While ShinyHunters’ initial PeopleSoft campaign focused on the education sector, the new wave of attacks has expanded to agriculture, government, healthcare, IT services, technology, and transportation organizations, Google says. As part of the new campaign, the hackers have been deploying web shells on dozens of systems after bypassing WAF rules using ‘%50’, the URL-encoded form of the character ‘P’, in the request path containing the string ‘\u002FPSEMHUB’. “Many WAF and reverse proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet. This allows the threat actor to reach the endpoint on systems whose operators may have believed their WAF rules had mitigated the exposure,” Google says. The attackers either sent multiple POST requests to access web shells behind some load-balanced environments, likely to ensure that a copy of the web shell is deployed on every WebLogic node, or sent POST requests that returned command output directly in the HTTP response to spawn the shell processes. Mandiant and GTIG observed the hacking group establishing persistence through two complementary, single-line JSP web shells, and deploying the SideEye backdoor on Windows servers to steal credentials from browsers and applications, manage files and processes, and gain reverse shell and reverse proxy capabilities. Additionally, the attackers deployed the open source Neo-reGeorg tunneling toolkit for internal discovery and lateral movement, and the open source remote management platform MeshCentral. The hackers executed commands with root or System privileges to perform host and user discovery and process verification, and abused PeopleSoft and WebLogic service accounts for gaining access to application data, configuration files, and database connection strings. PeopleSoft customers are advised to apply Oracle’s patches for CVE-2026-35273, to harden their environments, hunt for potential indicators of compromise (IoCs) and data theft, and prepare for extortion in the event of compromise. “UNC6240 has a well-established pattern of data theft extortion, that is, stealing data and threatening to release it on a data leak site unless the victim pays a ransom. Affected organizations should prepare for extortion communications and monitor for potential public exposure of stolen data,” Google says. Related: Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability Related: China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks Related: New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining Related: In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire New x47.c Windows Botnet Weaponizes xAI Grok, AI API DrainingKosovar Owner of Rydox Marketplace Pleads Guilty in US Court‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data ExfiltrationRoundcube Webmail Vulnerability in Attackers’ CrosshairsKontext Security Emerges With $4 Million for AI Agent Runtime ControlsAI-Powered Campaign Targets Hundreds of Online RetailersSolarWinds Patches Critical RCE Flaws in Observability Self-HostedAstrana Health Data Breach Impacts Private, Confidential Information Latest News Modulate Raises $25 Million to Advance Deepfake DetectionCall for Presentations Open for 2026 CISO Forum Virtual SummitPrison Sentence for Former US Soldier Who Hacked AT&T and VerizonDC Health Agency Exposes 400,000 Beneficiary RecordsNew Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy ProtectionsNvidia Unveils AI Agent Safety Platform With Hardware-Based WatchdogKiteworks Urges Server Shutdown, Finds Advanced Forms VulnerabilityCitrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveDoppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.Delinea has appointed Timothy Regan as Chief Financial Officer.Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.More People On The MoveExpert Insights Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fgoogle-warns-of-shinyhunters-fresh-oracle-peoplesoft-campaign\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F06\u002FOracle-PeopleSoft.jpeg","2026-09-28T10:56:46+00:00","2026-09-28T18:00:13.619777+00:00",9,[18,21,23,26,29,31],{"name":19,"type":20},"ShinyHunters","threat_actor",{"name":22,"type":20},"UNC6240",{"name":24,"type":25},"Oracle","vendor",{"name":27,"type":28},"Oracle PeopleSoft","product",{"name":30,"type":25},"Google",{"name":32,"type":25},"Mandiant","574f766a-fb3f-487c-8d2c-0720ae75471b",{"id":33,"icon":35,"name":36,"slug":37},null,"Zero-day","zero-day",[39,44,49,54],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":45},{"id":46,"icon":35,"name":47,"slug":48},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":50},{"id":51,"icon":35,"name":52,"slug":53},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":55},{"id":56,"icon":35,"name":57,"slug":58},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[60,64,67,70,73],{"type":61,"value":62,"context":63},"cve","CVE-2026-35273","Oracle PeopleSoft zero-day vulnerability in Environment Management Hub (PSEMHUB) allowing remote code execution without authentication",{"type":53,"value":65,"context":66},"SideEye","Backdoor deployed on Windows servers to steal credentials from browsers and applications, manage files and processes, and establish reverse shells",{"type":53,"value":68,"context":69},"Neo-reGeorg","Open source tunneling toolkit abused for internal discovery and lateral movement",{"type":53,"value":71,"context":72},"MeshCentral","Open source remote management platform deployed for command execution and control",{"type":74,"value":75,"context":76},"mitre_attack","T1505.004","Web shell deployment for persistence and command execution"]