ShinyHunters resumes exploitation of Oracle PeopleSoft vulnerability, warns Mandiant

Published:

A new campaign by the hacking group ShinyHunters is exploiting a vulnerability in Oracle’s PeopleSoft, as reported by Mandiant. This vulnerability, identified as CVE-2026-35273, has been leveraged against various sectors, including education and healthcare, following its disclosure in June 2026. Mandiant warns that ShinyHunters has adapted its tactics to target organizations that implemented workarounds instead of applying the official patch.

Middle East Relevance

While the immediate impact of this vulnerability on Middle Eastern organizations is not explicitly detailed, the widespread use of Oracle PeopleSoft in sectors such as government and education in the region raises concerns. Organizations utilizing this software should be aware of the potential risks associated with the vulnerability, especially if they have not applied the necessary patches.

Key Facts

  • The vulnerability CVE-2026-35273 affects Oracle’s PeopleSoft, widely used for managing business tasks.
  • ShinyHunters exploited this vulnerability as a zero-day between May 27 and June 9, 2026.
  • Oracle released a patch for the vulnerability on June 10, 2026.
  • Mandiant reported that ShinyHunters has expanded its targeting, deploying web shells on numerous systems globally.
  • ShinyHunters has a history of data theft and extortion, threatening to release stolen data unless a ransom is paid.

Technical Context

CVE-2026-35273 is a vulnerability in Oracle PeopleSoft that allows attackers to gain unauthorized access to sensitive data and systems. Mandiant’s analysis indicates that ShinyHunters has successfully exploited this vulnerability to obtain full control over compromised systems, accessing critical configuration files and application data. The group has adapted its methods to exploit organizations that have only implemented workarounds instead of applying the official patch.

Risk and Decision

Organizations using Oracle PeopleSoft must act promptly to mitigate risks associated with this vulnerability. The potential for data theft and extortion is significant, particularly for sectors like healthcare and education that handle sensitive information. It is crucial for IT and security teams to prioritize patching the vulnerability and monitoring for any suspicious activity related to human resources, payroll, and student records.

Defensive Guidance

Organizations should immediately review their systems for the application of the patch released by Oracle on June 10, 2026. If the patch has not been applied, it is essential to do so without delay. Additionally, organizations should monitor database logs for unusual queries and prepare for potential extortion communications from ShinyHunters, given their established pattern of data theft.

Source and evidence

The information in this article is based on a report by Mandiant, published on their blog on September 29, 2026, detailing the renewed exploitation of the Oracle PeopleSoft vulnerability by the ShinyHunters group. The report highlights the operational significance of the vulnerability and the ongoing threat posed by the group.

CWME will continue tracking regional implications as more verified information becomes available.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

CrowdStrike recognized as leader in Forrester Wave for proactive security platforms

CrowdStrike has been recognized as a Leader in The Forrester Wave: Proactive Security Platforms, Q3 2026, achieving the highest score in the Strategy category...

Microsoft tracks Storm-2570’s consistent tactics across multiple ransomware deployments

Microsoft has identified Storm-2570, a ransomware affiliate, as a significant threat actor employing consistent tactics across various ransomware deployments, including Qilin, DragonForce, Anubis, and...

Citrix NetScaler ADC and Gateway products affected by multiple critical CVEs

Citrix has disclosed multiple critical vulnerabilities affecting its NetScaler ADC and Gateway products, with at least two of these vulnerabilities, CVE-2026-88771 and CVE-2026-88772, reportedly...

AI is transforming product team dynamics, says Muhammad Danish

Artificial intelligence (AI) is fundamentally transforming product team dynamics, according to Muhammad Danish, Senior Director of Product Design at Emirates NBD. He highlights that...