Skip to content
24/7 prioritized emergency intake for critical business security incidents and web application compromises.
Security journal / ShinyHunters PeopleSoft Attack: Google Confirms 9.8 Zero Day Is Back

ShinyHunters PeopleSoft Attack: Google Confirms 9.8 Zero Day Is Back

Sep 27, 2026Baba Tanvir11 min read

Google has confirmed that the extortion group ShinyHunters has relaunched a mass exploitation campaign against Oracle PeopleSoft, reusing a critical vulnerability it originally exploited as a zero day back in June. The renewed activity, tracked by Google’s Mandiant and Threat Intelligence Group under the cluster name UNC6240, has already resulted in dozens of compromised systems across healthcare, transport, government, and education, with attackers deploying a new backdoor called SIDEEYE to maintain control of infected servers.

This isn’t a one off incident. It’s the second wave of a campaign that shows how a single unpatched vulnerability, combined with an over reliance on firewall level mitigations, can keep producing victims months after the original disclosure.

Table of Contents

  1. What Is CVE-2026-35273
  2. Timeline: Two Waves of Exploitation
  3. How ShinyHunters Bypassed the Firewall This Time
  4. What Is the SIDEEYE Backdoor
  5. Who Is Behind This: ShinyHunters and UNC6240
  6. How This Fits ShinyHunters’ Broader 2026 Track Record
  7. Which Sectors Were Hit
  8. The Extortion Model Behind This Attack
  9. Why Patching Alone Wasn’t Enough
  10. Why This Calls for Penetration Testing, Not Just Patching
  11. The Role of a SOC in Catching This Kind of Attack Early
  12. Indicators of Compromise Worth Reviewing
  13. What Organizations Should Do Now
  14. Lessons for ERP and Legacy System Security
  15. Frequently Asked Questions
  16. Get Your Systems Assessed

What Is CVE-2026-35273

CVE-2026-35273 is a critical, unauthenticated remote code execution vulnerability affecting Oracle PeopleSoft Enterprise PeopleTools, specifically its Environment Management Hub component, known as PSEMHUB. It carries a CVSS score of 9.8 out of 10, one of the highest severity ratings possible, because it requires no login, no user interaction, and only network access over HTTP to fully compromise a server. Oracle released an emergency security update for the flaw on June 10, 2026.

What makes this vulnerability particularly dangerous isn’t just its severity score. It’s the fact that PeopleSoft environments frequently host sensitive HR, payroll, student records, and finance data, all in one place, making a successful compromise far more valuable to an attacker than breaching a typical customer facing web application.

Timeline: Two Waves of Exploitation

This story actually spans two distinct campaigns, and keeping them separate matters for understanding your own exposure:

Wave one (May 27 to June 9, 2026): ShinyHunters, tracked by Google as UNC6240, exploited CVE-2026-35273 as a true zero day, meaning it was actively being used in attacks two full weeks before Oracle even knew the flaw existed. This first wave predominantly targeted higher education institutions, with more than 100 organizations notified by Mandiant and at least one confirmed victim, the University of Nottingham, which confirmed a breach affecting close to 500,000 current and former students.

Wave two (September 2026): Months after the patch was available, Google’s Threat Intelligence Group confirmedShinyHunters had relaunched the same campaign, this time against organizations that had implemented defensive WAF rules but had not actually applied Oracle’s patch. This renewed wave expanded well beyond education into healthcare, transport, and government sectors, with Google reporting dozens of compromised systems bearing web shells.

The gap between these two waves, roughly three months, is itself instructive. It shows that a patched but not yet widely applied vulnerability can remain a live threat far longer than most organizations assume.

How ShinyHunters Bypassed the Firewall This Time

According to Google’s own threat intelligence report, the group adapted specifically to the defensive guidance published after the first wave. Many organizations had put string based web application firewall rules in place to block requests to the vulnerable PSEMHUB endpoint, without actually patching the underlying flaw. ShinyHunters found that many of these WAF rules matched request paths before they were fully decoded, while the PeopleSoft application server itself decoded requests before routing them. By manipulating how a single character in the request path was encoded, the group was able to slip requests past pattern based filtering that never triggered on the underlying vulnerable endpoint. Google’s core message here is blunt: a web application firewall rule is not a substitute for patching, since encoding level tricks can defeat literal string matching entirely.

This detail also explains why some organizations that believed themselves protected were still compromised. Following defensive guidance from June without also completing the actual patch left a false sense of security that ShinyHunters specifically exploited months later.

What Is the SIDEEYE Backdoor

Once inside a compromised PeopleSoft server, ShinyHunters deployed a piece of malware Google has named SIDEEYE, a backdoor capable of stealing credentials and giving the attacker ongoing remote control over infected Windows servers. Rather than a one time smash and grab, a backdoor like this gives attackers a persistent foothold, allowing them to return to a compromised environment, move laterally to other internal systems, and continue exfiltrating data over time, all without needing to re exploit the original vulnerability.

This persistence mechanism is significant from a defender’s perspective. Even after a vulnerability is patched, a backdoor planted before the patch was applied can remain active, meaning organizations that only patch without also auditing for prior compromise may still be harboring an active foothold.

Who Is Behind This: ShinyHunters and UNC6240

ShinyHunters is a financially motivated extortion group that has been active since at least 2019, best known for large scale data theft rather than traditional ransomware. Google tracks the specific cluster behind this PeopleSoft activity as UNC6240, one of several related clusters, alongside others tied to Salesforce and SaaS focused intrusions, that security researchers increasingly describe as part of a broader, loosely affiliated ShinyHunters branded ecosystem rather than a single, fixed group. The PeopleSoft campaign marked a notable shift for the group, which has historically relied more on social engineering and stolen credentials than on direct software exploitation.

How This Fits ShinyHunters’ Broader 2026 Track Record

The PeopleSoft campaign didn’t happen in isolation. Throughout 2026, ShinyHunters branded activity has included large scale Salesforce customer breaches through stolen OAuth tokens, an extortion payment extracted from the company behind the Canvas learning platform, and, more recently, the group publicly seizing control of a rival ransomware gang’s own leak site. Taken together, this pattern shows a group willing to move fluidly between social engineering, SaaS token abuse, and now direct software exploitation, adapting its methods based on whichever approach yields the most valuable access at the time. Organizations shouldn’t treat the PeopleSoft campaign as an isolated technical fluke. It’s one chapter in a much larger, ongoing pattern of aggressive, opportunistic extortion.

Which Sectors Were Hit

Google’s renewed campaign report describes victims spanning healthcare, transport, government, and other sectors, a marked expansion from the first wave’s near exclusive focus on higher education. This broader targeting suggests the group scaled up its scanning and exploitation once the WAF bypass technique was refined, rather than deliberately choosing new industries one at a time. Any organization running an internet facing PeopleSoft deployment, regardless of industry, should consider itself a plausible target given this expansion.

The Extortion Model Behind This Attack

Unlike traditional ransomware, which encrypts files in place, ShinyHunters’ model centers on data theft and the threat of public exposure. Victims reportedly receive itemized lists of what was stolen, along with payment demands and tight deadlines, with proof samples sometimes hosted on public file sharing sites to pressure organizations into paying before a leak occurs. This pay or leak approach has become the group’s signature, distinct from encryption based ransomware but arguably just as disruptive, since it threatens reputational and regulatory consequences rather than simple operational downtime.

Why Patching Alone Wasn’t Enough

The most important lesson from this renewed campaign is that the organizations affected the second time around were not necessarily unpatched by neglect. Many had responded to public guidance by adding WAF rules to block the vulnerable endpoint, a reasonable interim step, but treated that mitigation as a permanent fix rather than a stopgap while patching was completed. This gap between “we blocked it at the firewall” and “we actually fixed it” is precisely what ShinyHunters exploited months later.

Why This Calls for Penetration Testing, Not Just Patching

Patch management alone tells you whether a known vulnerability has been fixed. It doesn’t tell you whether your compensating controls, like WAF rules, actually work the way you think they do. This is exactly the gap external penetration testing is designed to close: rather than checking a patch list, ethical hacking penetration testing actively attempts the same bypass techniques a real attacker would use, including encoding based WAF evasion, to confirm whether your defenses hold up in practice.

For internet facing ERP systems like PeopleSoft, a combination of internal and external penetration testing matters, since attackers who gain an initial foothold through an external flaw will typically attempt lateral movement internally next. Understanding your full penetration testing scope, covering both the perimeter and internal segmentation, is what actually validates whether an incident like this one could succeed against your environment. This is also why why penetration testing is important extends well beyond compliance checkbox exercises; it’s the only reliable way to know whether a documented mitigation genuinely holds up against a motivated, adaptive attacker.

The Role of a SOC in Catching This Kind of Attack Early

Even with strong patching and testing, some level of ongoing monitoring is necessary to catch an attack already underway. A security operations center, whether run internally or through a SOC as a service provider, gives organizations continuous visibility into unusual server behavior, like new remote access tools appearing on a server or unexpected outbound connections, both of which were hallmarks of the SIDEEYE backdoor’s deployment in this campaign. Pairing SOC monitoring with network security monitoring tools significantly shortens the window between initial compromise and detection, which is often the difference between catching a web shell early and discovering a full blown data leak months later.

Indicators of Compromise Worth Reviewing

While we won’t publish exploit level detail, security teams reviewing their own PeopleSoft environments should focus their investigation on a few general categories, based on Google’s public findings:

  • Unexpected remote access or remote monitoring software running on PeopleSoft application servers, particularly tools not part of your standard IT management stack
  • Unusual outbound network connections from PeopleSoft servers to unfamiliar domains
  • New or unexplained files placed within PeopleSoft application directories
  • Signs of credential use inconsistent with normal administrative patterns, especially around the Environment Management Hub component
  • Evidence of lateral movement attempts from PeopleSoft servers toward other internal systems

Any of these findings warrants a full incident response engagement rather than a simple cleanup, given the persistence capabilities SIDEEYE has demonstrated.

What Organizations Should Do Now

  1. Apply Oracle’s official security update for CVE-2026-35273 immediately if you haven’t already, rather than relying on WAF rules alone.
  2. Audit your PeopleSoft environment for signs of prior compromise, including unexpected web shells or unfamiliar remote access tools.
  3. Review your web application firewall configuration to understand its actual limitations, since encoding based bypasses can defeat literal pattern matching rules.
  4. Strengthen patch management processes so that emergency vendor advisories are treated with urgency rather than queued behind routine update cycles.
  5. Commission a third party penetration test to validate whether your specific WAF rules and network segmentation would actually stop this style of attack.
  6. Add SOC monitoring or a managed SIEM to catch backdoor deployment and lateral movement early, rather than relying solely on perimeter defenses.
  7. Review vendor and third party access to your ERP environment, since attackers frequently pivot through less monitored integration points once inside.

Lessons for ERP and Legacy System Security

Enterprise resource planning systems like PeopleSoft often run mission critical HR, finance, and student records functions, yet they frequently receive less security attention than customer facing applications. This incident is part of a broader pattern of ERP systems becoming attractive targets precisely because they’re data rich and comparatively under monitored. Any organization running legacy or on premises ERP software should treat it with the same rigor as its most exposed, internet facing systems, not as a quiet, internal tool, and should include it explicitly in cyber security consulting engagements rather than assuming a vendor’s own security is sufficient.

Frequently Asked Questions

What is CVE-2026-35273?
It’s a critical, unauthenticated remote code execution vulnerability in Oracle PeopleSoft’s Environment Management Hub, carrying a CVSS score of 9.8, that allows full server takeover over HTTP with no login required.

Did Google actually confirm this attack?
Yes. Google’s Mandiant and Threat Intelligence Group published a detailed report confirming renewed mass exploitation of the flaw by the cluster it tracks as UNC6240, associated with ShinyHunters.

What is the SIDEEYE backdoor?
It’s malware deployed after successful exploitation that steals credentials and gives attackers ongoing remote control over compromised Windows servers running PeopleSoft.

How is this different from the June 2026 attack?
The June campaign was a true zero day, exploited before Oracle even knew the flaw existed, primarily against universities. The September campaign targeted organizations that had added WAF protections but never actually patched the vulnerability.

Is my organization at risk if we already patched?
If you applied Oracle’s official June 10 security update, you are protected against this specific vulnerability. Risk remains for organizations that only implemented WAF rules without patching.

What sectors have been affected?
Higher education was hit hardest in the first wave. The renewed campaign expanded into healthcare, transport, and government sectors as well.

Is this connected to ShinyHunters’ other 2026 attacks?
It appears to be part of the same broader pattern of activity, alongside the group’s Salesforce token abuse campaigns and its extortion of the Canvas learning platform operator, suggesting a highly active, opportunistic threat actor rather than an isolated incident.

Why is penetration testing important in a case like this?
Because a WAF rule can look like protection on paper while still being bypassable in practice. Only active testing confirms whether a compensating control actually stops a real attacker’s technique.

How can my organization avoid becoming the next victim of a similar zero day?
A proactive vulnerability assessment and penetration test can identify unpatched or improperly mitigated systems before an attacker finds them, especially for internet facing ERP and legacy applications.

Get Your Systems Assessed

If your organization runs Oracle PeopleSoft or any similar ERP platform, this incident is a clear signal that firewall rules and delayed patch cycles are not enough on their own. Finding out exactly where your real exposure sits, before an attacker like ShinyHunters does, is the smarter move.

Book a penetration test with Nexus Web Security today

Previous briefingHow Ransomware Protection Works: 9 Powerful Layers Explained Next briefingTypes of Post-Quantum Cryptography Every Business Should Know