ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
Mandiant says ShinyHunters is again exploiting unpatched Oracle PeopleSoft flaw CVE-2026-35273, including after workarounds.
Mandiant warned that ShinyHunters has resumed exploiting CVE-2026-35273 in Oracle PeopleSoft, including against organizations that used published workarounds but did not apply Oracle's June 10 patch. The group exploited the bug as a zero-day from May 27 to June 9 against academic institutions and has now deployed web shells on dozens of systems across higher education, technology, healthcare, government, and other sectors. Compromises yielded operating-system control or access to configuration files, database connection strings, and application data, matching the group's data-theft extortion pattern. ShinyHunters also claimed an FBI jobs-site breach through PeopleSoft, and Dutch police arrested a suspected member in Amsterdam.