Security News

ShinyHunters Bypass Workarounds in Renewed Oracle PeopleSoft Attacks

The Record · 29 Sept 2026
Key Takeaway If your organisation used a temporary workaround for the PeopleSoft vulnerability instead of applying Oracle's official patch, prioritise patching immediately as attackers are now specifically targeting unpatched systems.

Security researchers at Mandiant have revealed that the hacking group ShinyHunters is running a renewed campaign exploiting CVE-2026-35273, a vulnerability in Oracle PeopleSoft. The flaw was first exploited as a zero-day between May and June, prompting Oracle to release an official patch on 10 June. Mandiant also published guidance at the time allowing organisations to apply temporary workarounds if they couldn't immediately install the patch.

According to Mandiant, ShinyHunters has now adapted its tactics to specifically target organisations that used those workarounds rather than installing the full patch. The group has deployed web shells on dozens of systems worldwide, affecting sectors including higher education, technology, IT services, healthcare, agriculture, transportation and government. In some cases, attackers gained full control of affected systems or accessed sensitive configuration files, database connection details and application data.

The renewed campaign follows ShinyHunters' claim of responsibility for a recent attack on an FBI jobs website, in which the group allegedly stole sensitive data on agency operations and staff. The FBI has told employees it is operating on the assumption that personal information for all staff may have been exfiltrated. PeopleSoft is widely used across government, education and healthcare organisations to manage core business functions, making this vulnerability a significant concern for a broad range of sectors.

Oracle PeopleSoft ShinyHunters vulnerability exploitation web shells patch management

Summarised by CISO AI from The Record. We link back to every original so you can read it yourself.