Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Andy Burnham: Northern PM’s long journey to power

    September 29, 2026

    Chris Mason: Burnham opens debate on huge issue of social care reform

    September 29, 2026

    A Pentagon Influencer Called Liberal Women a ‘Pestilence’ Who Will End Western Civilization

    September 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Andy Burnham: Northern PM’s long journey to power
    • Chris Mason: Burnham opens debate on huge issue of social care reform
    • A Pentagon Influencer Called Liberal Women a ‘Pestilence’ Who Will End Western Civilization
    • Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
    • Bitcoin Stabilizes Above Bulls’ Key Support Amid Bond Yield Surge
    • The ice blasting from Saturn’s moon Enceladus is stranger than scientists realized
    • This White House Plan Threatens Funding for Disabled Voters — ProPublica
    • As Wars Upend Export Routes, Turkey Is Turning Its Agricultural Heartland Into an Oil Hub
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 29, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Mandiant and Google Threat Intelligence Group (GTIG) over the weekend warned that the notorious extortion group ShinyHunters has launched a fresh mass-exploitation campaign targeting Oracle PeopleSoft customers.

    An integrated enterprise resource planning (ERP) software suite, PeopleSoft is used across numerous large enterprises for the management of core business functions, including finance, HR, payroll, and supply chain.

    Google’s warning comes four months after the hacking group was seen exploiting a zero-day vulnerability in PeopleSoft, tracked as CVE-2026-35273, to gain remote code execution without authentication.

    ShinyHunters, tracked by Google as UNC6240, targeted more than 100 PeopleSoft customers in June. Confirmed victims include the University of Nottingham in the UK, insurance regulators group NAIC, and Nissan.

    “This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint,” Mandiant and GTIG warn now.

    In the recent attack aimed at the FBI, ShinyHunters claimed to have leveraged a PeopleSoft zero-day. The hackers may be referring to this modified exploit rather than a new zero-day. 

    Advertisement. Scroll to continue reading.

    While ShinyHunters’ initial PeopleSoft campaign focused on the education sector, the new wave of attacks has expanded to agriculture, government, healthcare, IT services, technology, and transportation organizations, Google says.

    As part of the new campaign, the hackers have been deploying web shells on dozens of systems after bypassing WAF rules using ‘%50’, the URL-encoded form of the character ‘P’, in the request path containing the string ‘/PSEMHUB’.

    “Many WAF and reverse proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet. This allows the threat actor to reach the endpoint on systems whose operators may have believed their WAF rules had mitigated the exposure,” Google says.

    The attackers either sent multiple POST requests to access web shells behind some load-balanced environments, likely to ensure that a copy of the web shell is deployed on every WebLogic node, or sent POST requests that returned command output directly in the HTTP response to spawn the shell processes.

    Mandiant and GTIG observed the hacking group establishing persistence through two complementary, single-line JSP web shells, and deploying the SideEye backdoor on Windows servers to steal credentials from browsers and applications, manage files and processes, and gain reverse shell and reverse proxy capabilities.

    Additionally, the attackers deployed the open source Neo-reGeorg tunneling toolkit for internal discovery and lateral movement, and the open source remote management platform MeshCentral.

    The hackers executed commands with root or System privileges to perform host and user discovery and process verification, and abused PeopleSoft and WebLogic service accounts for gaining access to application data, configuration files, and database connection strings.

    PeopleSoft customers are advised to apply Oracle’s patches for CVE-2026-35273, to harden their environments, hunt for potential indicators of compromise (IoCs) and data theft, and prepare for extortion in the event of compromise.

    “UNC6240 has a well-established pattern of data theft extortion, that is, stealing data and threatening to release it on a data leak site unless the victim pays a ransom. Affected organizations should prepare for extortion communications and monitor for potential public exposure of stolen data,” Google says.

    Related: Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability

    Related: China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks

    Related: New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

    Related: In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

    campaign fresh Google Oracle PeopleSoft ShinyHunters warns
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

    Apple patches CoreGraphics zero-day flaw exploited in attacks

    Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’ 

    Aviva boss warns more homes will be uninsurable due to flood risk

    Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist

    80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Andy Burnham: Northern PM’s long journey to power

    September 29, 2026

    Chris Mason: Burnham opens debate on huge issue of social care reform

    September 29, 2026

    A Pentagon Influencer Called Liberal Women a ‘Pestilence’ Who Will End Western Civilization

    September 29, 2026

    Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

    September 29, 2026
    Latest Posts

    Perez Hilton death hoax spreads online after hospitalization

    August 7, 2026

    Selling Trust From Orbit

    August 7, 2026

    Ondo Finance hit by corporate control fight as founder’s mother seeks to oust CEO

    August 7, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Andy Burnham: Northern PM’s long journey to power

    September 29, 2026

    Chris Mason: Burnham opens debate on huge issue of social care reform

    September 29, 2026

    A Pentagon Influencer Called Liberal Women a ‘Pestilence’ Who Will End Western Civilization

    September 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.