29 SEP 2026 — ShinyHunters, the group behind this year's Oracle PeopleSoft data thefts, is back and now slips past the firewall rules many organisations used instead of patching. Google's threat researchers reported on 26 September that the group has compromised dozens of PeopleSoft systems worldwide with a modified version of its June exploit.
Oracle's June patch still stops the attack. A rule that blocks the vulnerable address does not.
What happened in June
In June, the group exploited CVE-2026-35273, a flaw in PeopleSoft that allowed code to run without a login, before Oracle had a fix. We reported Oracle's emergency patch on 16 June, and in July traced more than 100 breach disclosures to that single flaw.
Google's Mandiant and Threat Intelligence Group date that first wave to 27 May through 9 June, mostly against universities. Oracle's fix came in a security alert on 10 June.
What changed in September
The vulnerable component is PeopleSoft's Environment Management Hub, reached through a web path containing PSEMHUB. Many organisations that could not patch quickly added a rule to their web application firewall or reverse proxy blocking that path.
Google's report says the group now writes one letter of the path in encoded form. The firewall checks the raw text, finds no match and lets the request pass; the application server decodes the path and serves the vulnerable page as usual.
"WAF rules and path-based blocking are not a substitute for patching," the report says.
Who is being hit
The June wave was concentrated in higher education. The September wave reaches technology, IT services, healthcare, agriculture, transportation and government as well, across several regions.
Once inside, Google says, the group installs web shells, a backdoor it calls SIDEEYE hidden in a fake media-player installer, a tunnelling tool, and MeshAgent, a legitimate remote-management tool it uses to keep access. It steals records, threatens to publish them on a leak site, and demands payment.
SecurityWeek notes that the confirmed victims of the June campaign included the University of Nottingham, the insurance regulators' group NAIC and Nissan. No victims of the new wave have been named.
Which systems are affected
Oracle's security alert for CVE-2026-35273 covers PeopleSoft PeopleTools versions 8.61 and 8.62, the supported releases, according to the national vulnerability database. The flaw is in the Environment Management component and can be exploited over the web by an attacker with no account.
CISA added it to its catalogue of exploited flaws on 12 June. The new campaign does not use a new flaw. It finds PeopleSoft servers that never received the June fix.
What to do
Install Oracle's June security alert patch. Google calls this mandatory, and it is the only fix. Where PeopleSoft's Environment Management Hub is not needed, disable it or remove it.
Fix the firewall rules as well, so they match the decoded path rather than the raw text, and assume attackers will try other encodings and letter cases. Then go back through your logs. Search for encoded variants of the path, check the hub's directory for web-page files nobody installed, and hunt for MeshCentral agents and command shells started by the WebLogic server process.
Google also advises rotating every credential the PeopleSoft server could reach, including database, integration and cloud keys. Watch for large archive files or long outbound transfers that could mark stolen data. An organisation that relied on a firewall rule since June should treat the server as possibly compromised until those checks come back clean.