Mandiant and Google Threat Intelligence Group warned that ShinyHunters, tracked as UNC6240, has launched a new mass-exploitation campaign against Oracle PeopleSoft customers by modifying its exploit to bypass WAF rules. The group has deployed web shells, SideEye, Neo-reGeorg, and MeshCentral across multiple sectors while preparing for data theft extortion. #ShinyHunters #UNC6240 #OraclePeopleSoft #CVE-2026-35273 #PSEMHUB #SideEye #NeoReGeorg #MeshCentral
Keypoints
- ShinyHunters is targeting Oracle PeopleSoft customers in a fresh mass-exploitation campaign.
- The group modified its exploit to bypass WAF rules protecting the PSEMHUB endpoint.
- Victims span education, agriculture, government, healthcare, IT services, technology, and transportation.
- Attackers deployed web shells, SideEye, Neo-reGeorg, and MeshCentral for persistence and lateral movement.
- Google advises applying Oracle’s patch for CVE-2026-35273 and preparing for extortion.
Read More: https://www.securityweek.com/google-warns-of-shinyhunters-fresh-oracle-peoplesoft-campaign/