Twikup logo
Twikup
ShinyHunters Renew PeopleSoft Attacks as Google Warns of Global Exploitation

ShinyHunters Renew PeopleSoft Attacks as Google Warns of Global Exploitation

By Akshay Satija•Editor in Chief•September 27, 2026•Updated September 27, 2026•4 min read
Today
#ShinyHunters#Oracle PeopleSoft#Google Mandiant#Cybersecurity#CVE-2026-35273#Cyber Attack#PeopleSoft Vulnerability#Oracle Security#Data Security#Enterprise Security

Key Takeaways

  • Mandiant identified renewed mass exploitation of CVE-2026-35273 linked to UNC6240, tracked as ShinyHunters.
  • Attackers modified their exploit to bypass some web application firewall protections targeting the vulnerable PeopleSoft path.
  • Oracle confirms CVE-2026-35273 can allow unauthenticated remote code execution and has provided security updates.

ShinyHunters Renew PeopleSoft Attacks as Google Warns of Global Exploitation

Google's cybersecurity unit has warned of renewed mass exploitation targeting Oracle PeopleSoft software, with Mandiant identifying activity linked to UNC6240, tracked as ShinyHunters.

The renewed campaign involves CVE-2026-35273, a security vulnerability affecting Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62.

Mandiant Identifies Renewed Exploitation

According to Google Cloud's Mandiant threat intelligence report published on September 25, 2026, attackers have resumed mass exploitation of the PeopleSoft vulnerability after organizations introduced defensive measures following earlier attacks.

Mandiant said attackers modified their exploitation technique to bypass some Web Application Firewall protections. The revised method uses URL encoding to alter part of the vulnerable /PSEMHUB/ path while still reaching the targeted application.

The campaign has been observed across multiple sectors globally, including higher education, technology, IT services, healthcare, agriculture, transportation and government.

Mandiant also reported that web shells were deployed on dozens of systems around the world. Attackers used tools including MeshAgent and MeshCentral, which can provide persistent access to compromised environments.

Oracle Confirms the PeopleSoft Vulnerability

Oracle's official security advisory identifies the vulnerability as CVE-2026-35273.

The company says the vulnerability affects PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. Oracle classifies the vulnerability with a CVSS 3.1 score of 9.8.

The vulnerability is remotely exploitable without authentication and can potentially result in remote code execution.

Oracle's security advisory was initially released on June 10, 2026, and the company's June 2026 Critical Patch Update included fixes associated with the vulnerability.

Why Web Application Firewall Protection May Not Be Enough

The latest Mandiant findings show why organizations cannot necessarily rely on perimeter security controls alone when protecting vulnerable enterprise applications.

Attackers adapted the exploitation technique to bypass specific Web Application Firewall protections. This means an organization may have defensive rules in place while still remaining exposed if the underlying software vulnerability has not been patched.

Mandiant recommends addressing the vulnerability itself rather than depending solely on WAF-based blocking.

ShinyHunters Activity Expands Across Industries

Mandiant's observations indicate that the renewed campaign is not limited to one particular industry.

Organizations in education, technology, healthcare, transportation, agriculture, government and IT services have appeared within the observed activity.

The deployment of web shells on compromised systems also highlights the potential for attackers to establish continued access after successful exploitation.

Oracle PeopleSoft Users Face a Patch Priority

Organizations running affected PeopleTools versions should review Oracle's security guidance and determine whether their environments have received the relevant security updates.

Because CVE-2026-35273 can be remotely exploited without authentication, exposed PeopleSoft environments require particular attention.

Organizations should also review security logs and other available telemetry for signs of exploitation or unauthorized access, especially where vulnerable systems were exposed to external networks.

TwikUp's Perspective

The latest Mandiant findings highlight an important cybersecurity lesson for organizations running enterprise software: defensive layers such as Web Application Firewalls can reduce risk, but they should not replace vulnerability remediation.

The reported changes to the exploitation method demonstrate how attackers can adapt when organizations deploy blocking rules. Patching the underlying vulnerability therefore remains an important part of the defensive response.

For PeopleSoft users, the issue is particularly significant because the vulnerability can be exploited remotely without authentication. Organizations should therefore treat Oracle's security guidance as the primary reference for remediation and combine patching with appropriate monitoring for signs of compromise.

The available official sources establish renewed exploitation and the technical characteristics of CVE-2026-35273. They do not, however, establish that every organization using PeopleSoft has been compromised.

What Organizations Should Watch

Organizations using affected PeopleSoft environments should focus on three areas:

  • Applying the relevant Oracle security updates.
  • Reviewing Web Application Firewall and application logs for suspicious activity.
  • Investigating systems for indicators associated with unauthorized access or web-shell deployment.

The renewed campaign shows that cyber threats can evolve quickly after defensive measures are introduced. Keeping enterprise software patched remains a fundamental part of reducing exposure.

Sources

Google's Mandiant cybersecurity team has identified renewed mass exploitation targeting Oracle PeopleSoft through CVE-2026-35273. Attackers have modified their technique to bypass some Web Application Firewall protections, while Oracle confirms the vulnerability can enable unauthenticated remote code execution.

Frequently Asked Questions

FAQ

What is CVE-2026-35273?

CVE-2026-35273 is a security vulnerability affecting Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. Oracle says it can be remotely exploited without authentication and potentially lead to remote code execution.

Who is exploiting the PeopleSoft vulnerability?

Google Mandiant identified renewed exploitation activity associated with UNC6240, which Mandiant tracks as ShinyHunters.

How are attackers bypassing Web Application Firewall protections?

Mandiant reported that attackers modified their exploitation technique by using URL encoding within the vulnerable /PSEMHUB/ path to bypass some Web Application Firewall protections.

Which industries have been affected by the renewed campaign?

Mandiant reported activity across sectors including higher education, technology, IT services, healthcare, agriculture, transportation and government.

How can organizations protect PeopleSoft systems?

Organizations should apply the relevant Oracle security updates, review their security and application logs, and investigate systems for indicators of unauthorized access or web-shell deployment.

Reader supported

Enjoyed this story? Buy us a coffee.

Your voluntary support helps TwikUp create clear, useful Canadian news and explainers. Choose any amount—every contribution helps.

Support TwikUp

Secure checkout on PayPal. No physical product or charitable tax receipt is provided.