INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ShinyHunters Exploits Oracle PeopleSoft Flaw via WAF Bypass

| 2026-09-26 11:46 CRITICAL HIGH
Executive Summary AI-generated
The ShinyHunters extortion gang has been exploiting a zero-day vulnerability in Oracle PeopleSoft servers, allowing them to steal data from 100 organizations. The threat actors use an executable named 'Ple64.exe' that masquerades as a signed Light Alloy media player installer but installs a backdoor tracked by Google as SIDEEYE. ShinyHunters also deploy web shells on dozens of systems worldwide in higher education, technology, IT services, healthcare, agriculture, transportation, and government organizations using compromised Windows servers. The gang is targeting vulnerable Oracle PeopleSoft servers with the CVE-2026-35273 flaw, which allows unauthenticated remote code execution. Mandiant urges organizations to install the latest security update to protect against this vulnerability.
Technical Mitigations AI-generated
* Use the latest security update to protect against CVE-2026-35273, as it allows unauthenticated remote code execution and provides a more robust defense against WAF bypass tricks. * Implement additional remediation and hardening guidance for Oracle PeopleSoft systems running vulnerable versions of the software, including: - Searching WebLogic access logs for requests to '/PSEMHUB/' and encoded variants such as '/%50SEMHUB/'. - Monitoring for signs of exploitation, such as POST requests containing serialized Java objects returning information about the host operating system without writing files or disrupting service. * Consider implementing a web application firewall (WAF) bypass mitigation strategy that detects and blocks percent-encoded versions of URLs like '/PSEMHUB/', rather than relying solely on WAF rules designed to block literal paths.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters Neo-reGeorgNeo-reGeorg CVE-2026-35273CVE-2026-35273
Target & Sectors
Global Scope educationeducation healthcarehealthcare technologytechnology transportationtransportation mediamedia governmentgovernment
Incident Timeline
‎May 2026
The ShinyHunters group targeted the FBI after a May 2026 public advisory detailing its tactics and warning victims against paying stole about 2-3 TB of sensitive data from the U.S. Federal Bureau of Investigation's FBIJobs.gov portal.
threat_actor ShinyHunters
data_breach 2 TB
attribution FBI
attribution Learning Management System
attribution LMS
‎June 10
ShinyHunters used a zero-day vulnerability in Oracle PeopleSoft to breach the systems of 100 global organizations on June 10.
tactic Extortion
threat_actor ShinyHunters
victims 100 global organizations
organisation BleepingComputer
‎June 2026
ShinyHunters exploited a previously unknown vulnerability in PeopleSoft, CVE-2026-35273.
vulnerability CVE-2026-35273
threat_actor ShinyHunters
‎September 22
ShinyHunters used a zero-day attack to gain remote code execution on the FBI Jobs platform, allowing them to access and spread laterally into the FBI's AWS GovCloud infrastructure.
tactic Remote Code Execution
threat_actor ShinyHunters
attribution FBI
data_breach 23 September
‎Sep 23, 2026
Threat actors used a zero-day exploit in PeopleSoft to gain unauthorized access to ShinyHunters' system.
‎September 23, 2026
ShinyHunters used a PeopleSoft zero-day attack to breach the FBI.
threat_actor ShinyHunters
attribution FBI
‎Sep 26, 2026
Threat actors exploited a previously unknown vulnerability in PeopleSoft, allowing them to gain unauthorized access and breach the FBI's internal systems.
‎2026/09/26
ShinyHunters claimed to have breached the U.S. Federal Bureau of Investigation (FBI) and stolen sensitive information belonging to FBI employees and job applicants via a zero-day vulnerability in Oracle PeopleSoft.
threat_actor ShinyHunters
organisation Google
organisation Mandiant
organisation MeshCentral
organisation SSH
organisation PeopleSoft
organisation CVE-2026-35273
organisation Data Breach / Cybercrime
organisation the U.S. Federal Bureau of Investigation
organisation The Register
organisation GnosticPlayers
infrastructure Windows
infrastructure Linux
organisation MeshAgent
organisation Oracle PeopleSoft
organisation JSP
organisation TCP
organisation RMM
data_breach 2 TB
data_breach 3 TB
organisation IP
victims 100 global organizations
organisation the Environment Management Hub
organisation POST
organisation WebLogic
organisation Disable the Environment Management Hub
organisation Rotate
organisation Reuters
organisation Oracle WebLogic
organisation HTTPS
organisation NFL
organisation CHANEL
organisation OAuth
organisation Social Security
data_breach 5,000 records
organisation the white board
organisation Clock
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
victims
100
Global Organizations
Metrics
data_breach
2
Tb
Metrics
infrastructure
‎Windows
Affected Product
Metrics
data_breach
3
Tb
Metrics
data_breach
5,000
Records
Metrics
data_breach
23
September