ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns

ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
ShinyHunters is exploiting Oracle PeopleSoft CVE-2026-35273 again, targeting organizations that applied workarounds but never patched the flaw. Mandiant says the group has deployed web shells across multiple sectors worldwide and recently claimed a breach of the FBIโ€™s jobs site. #ShinyHunters #Oracle #PeopleSoft #CVE-2026-35273 #FBI

Keypoints

  • Mandiant says ShinyHunters resumed exploiting Oracle PeopleSoft CVE-2026-35273.
  • The group targeted organizations that used workarounds instead of installing Oracleโ€™s patch.
  • Compromised systems were found across higher education, healthcare, technology, and government.
  • The attackers used the flaw to gain control and steal configuration files, database strings, and application data.
  • ShinyHunters also claimed responsibility for an FBI website attack and data theft extortion.

Read More: https://therecord.media/shinyhunters-cyberattacks-oracle-mandiant