The notorious cybercriminal collective ShinyHunters has launched a fresh wave of large-scale assaults against entities utilizing Oracle PeopleSoft software. Google’s cybersecurity division, Mandiant, reports that the hackers have discovered a novel method to bypass security patches implemented following a previous campaign.
Attackers Change Tactics to Slip Past Defenses
According to Mandiant, the threat actors continue to exploit a vulnerability within the Environment Management feature of PeopleSoft. However, the scope of the campaign has expanded beyond the initial focus on universities to impact organizations across the technology, healthcare, agriculture, transport, government, and IT services sectors.
Initially tracked as CVE-2026-35273, the vulnerability was actively exploited between May 27 and June 9, targeting higher education institutions during that early window. Oracle subsequently issued a security advisory on June 10 following the disclosure of the attacks.
In response to companies establishing firewall rules to block direct access to the vulnerable system path known as PSEMHUB, the hackers modified their exploitation technique. By employing a URL-encoding trick to obscure a portion of their requests, the attackers successfully reached the vulnerable endpoint on systems that relied solely on firewall protections rather than applying Oracle’s official patch.
Also Read: Ledger Unifies Security Leadership as AI Crypto Attacks Rise
Web Shells Used to Maintain Access
The latest incursions involve the deployment of web shells on compromised systems, granting the perpetrators persistent control and the ability to pivot deeper into corporate networks. Mandiant also noted indications that the group actively attempted to mask its footprint while conducting reconnaissance on impacted environments.
Google strongly advises organizations operating PeopleSoft to deploy Oracle’s official software patch rather than relying exclusively on network firewalls. Additional recommendations include disabling the Environment Management Hub when it is not in active use, reviewing WebLogic access logs, and thoroughly auditing PeopleSoft servers for unauthorized or anomalous files.
Because PeopleSoft is a critical platform heavily relied upon for human resources and essential enterprise operations, any underlying vulnerability presents a severe risk of exposing sensitive corporate and employee records. Notably, ShinyHunters has claimed access to data associated with the FBI via this identical vulnerability. Reuters has reported that the FBI is actively investigating the assertion, though official confirmation is pending.
Administrators overseeing PeopleSoft infrastructure are urged to take immediate action by applying the necessary patches, validating prior mitigation strategies, and thoroughly hunting for indicators of compromise within their networks.




