Cyberreport
ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
The brief
Mandiant describes renewed exploitation of Oracle PeopleSoft systems that remain vulnerable to CVE-2026-35273. The campaign reached organizations relying on web-application-firewall rules without applying Oracle’s patch, with attackers adapting requests to evade those rules. The report recommends patching or disabling the affected service, investigating application logs and deployed files, and rotating credentials exposed to the PeopleSoft service account.
AI-assisted brief
Source Google Threat Intelligence
Read full article

