

Hacking group ShinyHunters has restarted large-scale attacks on organizations using Oracle PeopleSoft software. The group found a new way around security measures that were added after an earlier round of attacks, according to Google's cybersecurity team, Mandiant.
Mandiant said the group is still using a flaw in PeopleSoft's Environment Management feature. This time, the attacks are not limited to universities. They have hit systems in technology, healthcare, agriculture, transport, government, and IT services.
The flaw, tracked as CVE-2026-35273, was first exploited between May 27 and June 9. Attackers mainly targeted universities during that early phase. Oracle sent out a security alert on June 10 after the attacks came to light.
Since then, the hackers have changed how they exploit the flaw. Many companies had set up firewall rules to stop direct access to the vulnerable system path called PSEMHUB. To get past this, attackers used a coding trick to hide part of their request. This let them reach the same weak point on systems that had firewall protection but had not yet installed Oracle's patch.
Also Read: Ledger Unifies Security Leadership as AI Crypto Attacks Rise
The renewed attacks involved placing web shells on hacked systems. These tools let attackers keep control and move around inside a network. Mandiant said it also saw signs of the group trying to stay hidden while exploring affected systems.
Google has asked companies running PeopleSoft to install Oracle's official patch instead of depending only on firewall rules. It also suggests turning off the Environment Management Hub when not needed, checking WebLogic access logs, and looking for unusual files on PeopleSoft servers.
PeopleSoft is widely used for human resources and other core business tasks. This makes any flaw in it a serious risk, since it can expose sensitive employee and company data. ShinyHunters has also said it accessed data linked to the FBI through this same flaw. Reuters reported that the FBI is looking into the claim but has not confirmed it.
Security teams managing PeopleSoft systems are being told to act fast. They should apply the patch, check earlier defenses, and scan for signs that attackers may already be inside their systems.