# ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

Publisher-attributed story with a reviewed brief or permitted publisher paragraph. The original publisher is responsible for the linked reporting.

- Publisher: Google Threat Intelligence
- Author credit: Mandiant
- Category: Cyber
- Original publication time: 2026-09-25T14:00:00Z
- First observed by NexusTechWire: 2026-10-01T20:28:45Z
- Original source: https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft/
- NexusTechWire record: https://nexustechwire.com/news/news-0d4d5cdcaf33895358b5

## The brief

Mandiant describes renewed exploitation of Oracle PeopleSoft systems that remain vulnerable to CVE-2026-35273. The campaign reached organizations relying on web-application-firewall rules without applying Oracle’s patch, with attackers adapting requests to evade those rules. The report recommends patching or disabling the affected service, investigating application logs and deployed files, and rotating credentials exposed to the PeopleSoft service account.

AI-assisted NexusTechWire summary, checked against the linked source on 2026-10-01T20:26:11.940Z. Not independent reporting.

Read the full original: [Google Threat Intelligence](https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft/)

This record does not reproduce the complete article or represent independent confirmation of every source claim.
