Close Menu
NCIJ Network NCIJ Network
    What's Hot

    As Wars Upend Export Routes, Turkey Is Turning Its Agricultural Heartland Into an Oil Hub

    September 29, 2026

    LPU Phagwara: A rape rumour sends an Indian university into turmoil and empties hostels

    September 29, 2026

    Andy Burnham expected to say he will push ahead with electoral reform plans | Electoral reform

    September 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • As Wars Upend Export Routes, Turkey Is Turning Its Agricultural Heartland Into an Oil Hub
    • LPU Phagwara: A rape rumour sends an Indian university into turmoil and empties hostels
    • Andy Burnham expected to say he will push ahead with electoral reform plans | Electoral reform
    • 19 Best Gifts for Plant Lovers and Gardeners (2026)
    • Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
    • Trezor Safe 7 Review: The FOSS Self Custody Hardware Wallet
    • Scrapping pensions triple lock ‘morally wrong’, says union boss
    • As yellow-eyed penguins disappear, conservationists focus on deaths in fishing nets
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 29, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Mandiant and Google Threat Intelligence Group (GTIG) over the weekend warned that the notorious extortion group ShinyHunters has launched a fresh mass-exploitation campaign targeting Oracle PeopleSoft customers.

    An integrated enterprise resource planning (ERP) software suite, PeopleSoft is used across numerous large enterprises for the management of core business functions, including finance, HR, payroll, and supply chain.

    Google’s warning comes four months after the hacking group was seen exploiting a zero-day vulnerability in PeopleSoft, tracked as CVE-2026-35273, to gain remote code execution without authentication.

    ShinyHunters, tracked by Google as UNC6240, targeted more than 100 PeopleSoft customers in June. Confirmed victims include the University of Nottingham in the UK, insurance regulators group NAIC, and Nissan.

    “This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint,” Mandiant and GTIG warn now.

    In the recent attack aimed at the FBI, ShinyHunters claimed to have leveraged a PeopleSoft zero-day. The hackers may be referring to this modified exploit rather than a new zero-day. 

    Advertisement. Scroll to continue reading.

    While ShinyHunters’ initial PeopleSoft campaign focused on the education sector, the new wave of attacks has expanded to agriculture, government, healthcare, IT services, technology, and transportation organizations, Google says.

    As part of the new campaign, the hackers have been deploying web shells on dozens of systems after bypassing WAF rules using ‘%50’, the URL-encoded form of the character ‘P’, in the request path containing the string ‘/PSEMHUB’.

    “Many WAF and reverse proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet. This allows the threat actor to reach the endpoint on systems whose operators may have believed their WAF rules had mitigated the exposure,” Google says.

    The attackers either sent multiple POST requests to access web shells behind some load-balanced environments, likely to ensure that a copy of the web shell is deployed on every WebLogic node, or sent POST requests that returned command output directly in the HTTP response to spawn the shell processes.

    Mandiant and GTIG observed the hacking group establishing persistence through two complementary, single-line JSP web shells, and deploying the SideEye backdoor on Windows servers to steal credentials from browsers and applications, manage files and processes, and gain reverse shell and reverse proxy capabilities.

    Additionally, the attackers deployed the open source Neo-reGeorg tunneling toolkit for internal discovery and lateral movement, and the open source remote management platform MeshCentral.

    The hackers executed commands with root or System privileges to perform host and user discovery and process verification, and abused PeopleSoft and WebLogic service accounts for gaining access to application data, configuration files, and database connection strings.

    PeopleSoft customers are advised to apply Oracle’s patches for CVE-2026-35273, to harden their environments, hunt for potential indicators of compromise (IoCs) and data theft, and prepare for extortion in the event of compromise.

    “UNC6240 has a well-established pattern of data theft extortion, that is, stealing data and threatening to release it on a data leak site unless the victim pays a ransom. Affected organizations should prepare for extortion communications and monitor for potential public exposure of stolen data,” Google says.

    Related: Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability

    Related: China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks

    Related: New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

    Related: In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

    campaign fresh Google Oracle PeopleSoft ShinyHunters warns
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Apple patches CoreGraphics zero-day flaw exploited in attacks

    Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’ 

    Aviva boss warns more homes will be uninsurable due to flood risk

    Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist

    80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

    DC Health Agency Exposes 400,000 Beneficiary Records

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    As Wars Upend Export Routes, Turkey Is Turning Its Agricultural Heartland Into an Oil Hub

    September 29, 2026

    LPU Phagwara: A rape rumour sends an Indian university into turmoil and empties hostels

    September 29, 2026

    Andy Burnham expected to say he will push ahead with electoral reform plans | Electoral reform

    September 29, 2026

    19 Best Gifts for Plant Lovers and Gardeners (2026)

    September 29, 2026
    Latest Posts

    Perez Hilton death hoax spreads online after hospitalization

    August 7, 2026

    Selling Trust From Orbit

    August 7, 2026

    Ondo Finance hit by corporate control fight as founder’s mother seeks to oust CEO

    August 7, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    As Wars Upend Export Routes, Turkey Is Turning Its Agricultural Heartland Into an Oil Hub

    September 29, 2026

    LPU Phagwara: A rape rumour sends an Indian university into turmoil and empties hostels

    September 29, 2026

    Andy Burnham expected to say he will push ahead with electoral reform plans | Electoral reform

    September 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.