ShinyHunters adapts past Oracle PeopleSoft workarounds, Mandiant says
Organizations that applied the published mitigation without patching are now being hit, Mandiant found web shells on dozens of systems globally.
TL;DR
Mandiant warned Friday that ShinyHunters has resumed exploiting CVE-2026-35273, an Oracle PeopleSoft vulnerability patched June 10. The group is now targeting organizations that applied Mandiant's recommended workarounds but skipped the patch. The new campaign spans higher education, technology, IT services, healthcare, agriculture, transportation, and government. Mandiant says the attackers have deployed web shells on dozens of systems and can gain access to PeopleSoft configuration files, database connection strings, and application data. ShinyHunters last week claimed its breach of the FBI's jobs site came through an Oracle PeopleSoft vulnerability.
Mandiant published findings Friday showing that ShinyHunters has restarted exploitation of CVE-2026-35273, a PeopleSoft vulnerability the firm reported in June as a zero-day in attacks on academic institutions between May 27 and June 9. Oracle released a patch on June 10. Mandiant's accompanying guidance gave organizations two paths: patch, or apply workarounds.
The new campaign targets the second group. Mandiant said ShinyHunters "adapted to published defensive guidance, targeting organizations that implemented [workarounds] but did not patch the vulnerability." The attackers have deployed web shells on dozens of systems spanning higher education, technology, IT services, healthcare, agriculture, transportation, and government.
Once in, Mandiant found the group was able to "pivot into obtaining full control of an operating system or at least gain access to PeopleSoft configuration files, database connection strings, and application data."
The timing puts ShinyHunters' claim about the FBI breach under a sharper light. Last week the group took credit for defacing the FBI's jobs site and said it gained access through an Oracle PeopleSoft vulnerability. While Mandiant hasn't confirmed that link, the firm noted ShinyHunters' "well-established pattern of data theft extortion" and urged affected organizations to "prepare for extortion communications and monitor for potential public exposure of stolen data."
Mandiant recommended reviewing database logs for queries against human resources, payroll, and student records tables, the data categories ShinyHunters typically hunts.
Published ·Deep Fathom