Cyber Threat Intel 4 min read

The PeopleSoft Attackers Are Back, and Firewall Rules No Longer Stop Them

Google says ShinyHunters now slips past rules that blocked June's exploit and has hit dozens of systems. Oracle's June patch still works.

Priya Nair
Data, AI Governance & Policy Analyst
Published 29 Sep 2026, 6:32 AM (SGT)
Share:
Server hardware in a rack lit in blue Server hardware in a rack lit in blue Photo by cookieone on Pixabay
Advertisement

29 SEP 2026 — ShinyHunters, the group behind this year's Oracle PeopleSoft data thefts, is back and now slips past the firewall rules many organisations used instead of patching. Google's threat researchers reported on 26 September that the group has compromised dozens of PeopleSoft systems worldwide with a modified version of its June exploit.

Oracle's June patch still stops the attack. A rule that blocks the vulnerable address does not.

What happened in June

In June, the group exploited CVE-2026-35273, a flaw in PeopleSoft that allowed code to run without a login, before Oracle had a fix. We reported Oracle's emergency patch on 16 June, and in July traced more than 100 breach disclosures to that single flaw.

Google's Mandiant and Threat Intelligence Group date that first wave to 27 May through 9 June, mostly against universities. Oracle's fix came in a security alert on 10 June.

What changed in September

The vulnerable component is PeopleSoft's Environment Management Hub, reached through a web path containing PSEMHUB. Many organisations that could not patch quickly added a rule to their web application firewall or reverse proxy blocking that path.

Google's report says the group now writes one letter of the path in encoded form. The firewall checks the raw text, finds no match and lets the request pass; the application server decodes the path and serves the vulnerable page as usual.

"WAF rules and path-based blocking are not a substitute for patching," the report says.

CVE-2026-35273The same PeopleSoft flaw as June's zero-day
10 JuneOracle's fix, which still blocks the new wave
DozensSystems compromised in the renewed campaign
7Sectors hit, up from mostly universities in June

Who is being hit

The June wave was concentrated in higher education. The September wave reaches technology, IT services, healthcare, agriculture, transportation and government as well, across several regions.

Once inside, Google says, the group installs web shells, a backdoor it calls SIDEEYE hidden in a fake media-player installer, a tunnelling tool, and MeshAgent, a legitimate remote-management tool it uses to keep access. It steals records, threatens to publish them on a leak site, and demands payment.

SecurityWeek notes that the confirmed victims of the June campaign included the University of Nottingham, the insurance regulators' group NAIC and Nissan. No victims of the new wave have been named.

Which systems are affected

Oracle's security alert for CVE-2026-35273 covers PeopleSoft PeopleTools versions 8.61 and 8.62, the supported releases, according to the national vulnerability database. The flaw is in the Environment Management component and can be exploited over the web by an attacker with no account.

Advertisement

CISA added it to its catalogue of exploited flaws on 12 June. The new campaign does not use a new flaw. It finds PeopleSoft servers that never received the June fix.

What to do

Install Oracle's June security alert patch. Google calls this mandatory, and it is the only fix. Where PeopleSoft's Environment Management Hub is not needed, disable it or remove it.

Fix the firewall rules as well, so they match the decoded path rather than the raw text, and assume attackers will try other encodings and letter cases. Then go back through your logs. Search for encoded variants of the path, check the hub's directory for web-page files nobody installed, and hunt for MeshCentral agents and command shells started by the WebLogic server process.

Google also advises rotating every credential the PeopleSoft server could reach, including database, integration and cloud keys. Watch for large archive files or long outbound transfers that could mark stolen data. An organisation that relied on a firewall rule since June should treat the server as possibly compromised until those checks come back clean.

Advertisement
Priya Nair
Data, AI Governance & Policy Analyst

Priya Nair covers AI governance, data protection, privacy, and digital trust topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Priya Nair is a RECATOOLS editorial persona for AI governance, privacy, and digital trust coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement