Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ShinyHunters Target Oracle PeopleSoft in New Cyber Campaign

ShinyHunters Target Oracle PeopleSoft in New Cyber Campaign

Posted on September 28, 2026 By CWS

Mandiant and Google’s Threat Intelligence Group (GTIG) have recently alerted organizations about a renewed cyber offensive by ShinyHunters, targeting Oracle PeopleSoft users. This notorious group is known for its extortion techniques and has now set its sights on a wide array of industries using this enterprise resource planning software.

Understanding the PeopleSoft Threat

Oracle’s PeopleSoft, an ERP suite crucial for managing functions like finance, HR, and supply chain, is widely used by major enterprises. Google has raised concerns following an incident four months ago where ShinyHunters exploited a zero-day vulnerability, identified as CVE-2026-35273, allowing unauthorized remote code execution.

In June, over 100 PeopleSoft clients were targeted, including entities such as the University of Nottingham, NAIC, and Nissan. The attackers have adapted their methods to bypass existing web application firewall rules, enhancing their exploit’s effectiveness.

Scope and Impact of the Cyber Campaign

The latest attacks have broadened from the initial focus on educational institutions to include sectors like agriculture, government, healthcare, IT, and transportation. By circumventing firewall rules using encoded URL paths, ShinyHunters have managed to deploy web shells on numerous systems, thus compromising their security.

These cybercriminals have been observed using POST requests to either deploy web shells across load-balanced environments or execute commands directly. Additionally, they have maintained persistence through JSP web shells and installed the SideEye backdoor on Windows servers for further exploitation.

Mitigation and Prevention Strategies

Organizations using PeopleSoft are strongly advised to install Oracle’s patches for the CVE-2026-35273 vulnerability. Strengthening security measures, searching for indicators of compromise, and preparing for potential extortion attempts are crucial steps to safeguard against this threat.

ShinyHunters have a history of data theft and ransom demands, threatening to leak data unless paid. Companies should be vigilant for any signs of their data appearing on leak sites and prepare for possible extortion communications.

By applying these preventive measures, organizations can better protect themselves against the ongoing threat posed by ShinyHunters and similar cybercriminal groups.

Security Week News Tags:cyber attack, Cybersecurity, data breach, data extortion, ERP software, Oracle PeopleSoft, PeopleSoft security, ShinyHunters, web shells, zero-day vulnerability

Post navigation

Previous Post: Carbonato Botnet Targets Docker Hosts with Hermes AI
Next Post: Kiteworks Advises Server Shutdown Amid Threat Intelligence

Related Posts

Zero-Day Vulnerability Hits Adobe Commerce Platforms Zero-Day Vulnerability Hits Adobe Commerce Platforms Security Week News
McDonald’s Chatbot Recruitment Platform Leaked 64 Million Job Applications McDonald’s Chatbot Recruitment Platform Leaked 64 Million Job Applications Security Week News
Ivanti Releases Crucial Patches for Endpoint Manager Ivanti Releases Crucial Patches for Endpoint Manager Security Week News
Identity Is the New Perimeter: Why Proofing and Verification Are Business Imperatives Identity Is the New Perimeter: Why Proofing and Verification Are Business Imperatives Security Week News
Cisco Patches Critical Vulnerabilities in Contact Center Appliance Cisco Patches Critical Vulnerabilities in Contact Center Appliance Security Week News
Project Eleven Raises  Million for Post-Quantum Security Project Eleven Raises $20 Million for Post-Quantum Security Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Bitget Security Breach Results in $387 Million Loss
  • Nvidia Launches AI Safety Platform with Hardware Watchdog
  • Major Cybersecurity Incidents: Crypto Heist and Citrix Flaws
  • Kiteworks Advises Server Shutdown Amid Threat Intelligence
  • ShinyHunters Target Oracle PeopleSoft in New Cyber Campaign

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Bitget Security Breach Results in $387 Million Loss
  • Nvidia Launches AI Safety Platform with Hardware Watchdog
  • Major Cybersecurity Incidents: Crypto Heist and Citrix Flaws
  • Kiteworks Advises Server Shutdown Amid Threat Intelligence
  • ShinyHunters Target Oracle PeopleSoft in New Cyber Campaign

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark