Open Menu Close Menu
User
Scroll arrow
World

ShinyHunters Expands Oracle PeopleSoft Attacks

Dozens of Systems Compromised as Hackers Bypass Defences

Author
By TheZeal
Published: 26th Sep 2026, 11:20 PM
Illustration of an Umbreon-inspired hacker using a laptop in a dark data centre, connected by cable to a wall of servers, referencing ShinyHunters’ use of Umbreon imagery.
Illustration of an Umbreon-inspired hacker using a laptop in a dark data centre, connected by cable to a wall of servers, referencing ShinyHunters’ use of Umbreon imagery.

Hacking group ShinyHunters has renewed a mass exploitation campaign targeting Oracle PeopleSoft, compromising dozens of systems worldwide after finding a simple way around protections introduced following earlier attacks.

Google’s Mandiant threat-intelligence unit says the latest activity has spread well beyond the universities predominantly targeted during the group’s earlier campaign.

Compromised systems have now been identified across higher education, technology, IT services, healthcare, agriculture, transportation and government. Mandiant has not publicly named the affected organisations.

The attacks exploit CVE-2026-35273, a critical Oracle PeopleSoft vulnerability that allows hackers to remotely execute code on vulnerable systems without authentication.

Oracle issued an emergency security update for the flaw in June, but some organisations remained unpatched and relied on web application firewall rules designed to block requests to the vulnerable PeopleSoft component.

ShinyHunters appears to have found a remarkably simple way around some of those protections. Mandiant says the hackers altered a single character in the malicious web request by using its URL-encoded equivalent, allowing the request to bypass some firewall rules while still being accepted by PeopleSoft.

Once inside, the hackers have been observed deploying web shells, backdoors and remote-access tools. Mandiant says some commands executed with root or SYSTEM-level privileges, giving the hackers the highest level of operating-system access on affected servers.

Separately, ShinyHunters has told BleepingComputer that it recently discovered another previously unknown PeopleSoft vulnerability and is using it against additional organisations, including Fortune 500 companies. The claim has not been independently verified, and the companies have not been named.

The developments follow ShinyHunters’ claimed breach of FBI recruitment systems using an alleged newly discovered PeopleSoft zero-day. The FBI has confirmed it is investigating the incident, which TheZeal reported on separately.

Mandiant is urging organisations running PeopleSoft to apply Oracle’s security update rather than relying on firewall rules alone, and to investigate systems for signs of unauthorised access and possible data theft.

Join the Discussion
What do you think?
No account required. Comment as a guest.
0 COMMENTS:
Home Latest
NZ Videos
Video LibraryLibrary
Menu Menu