#OraclePeopleSoft
ShinyHunters is using URL encoding to bypass WAF rules and keep exploiting Oracle PeopleSoft CVE-2026-35273, deploying web shells and backdoors against education, healthcare, and government targets. #ShinyHunters #OraclePeopleSoft #UNC6240
ShinyHunters Uses WAF Bypass Trick In Oracle PeopleSoft Attacks
ShinyHunters is using a URL-encoding trick to bypass WAF rules and keep exploiting Oracle PeopleSoft CVE-2026-35273 on unpatched servers. The group is deploying web shells and backdoors to steal data, move laterally, and maintain access across multiple sectors, including higher education and government. #ShinyHunters #UNC6240 #OraclePeopleSoft #CVE-2026-35273 #SIDEEYE #Neo-reGeorg #MeshAgent
www.hendryadrian.com
September 26, 2026 at 9:15 PM
ShinyHunters resumed mass exploitation of Oracle PeopleSoft CVE-2026-35273, bypassing WAF rules with a percent-encoded path and deploying web shells, Neo-ReGeorg tunnels, and MeshAgent across multiple sectors. #ShinyHunters #OraclePeopleSoft #UNC6240
ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
Mandiant and GTIG report renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), which bypasses WAF rules by using a percent-encoded /%50SEMHUB/ path to reach Oracle PeopleSoft’s vulnerable PSEMHUB endpoint. The campaign spans multiple sectors worldwide and uses web shells, SIDEEYE via a trojanized Ple64.exe installer, Neo-reGeorg tunnels, and MeshAgent for persistence and lateral movement. #UNC6240 #ShinyHunters #CVE-2026-35273 #OraclePeopleSoft #SIDEEYE #Ple64.exe #Neo-reGeorg #MeshAgent
www.hendryadrian.com
September 26, 2026 at 4:00 PM
ShinyHunters claims it used an unpatched Oracle PeopleSoft zero-day to breach FBI systems, move into AWS GovCloud, and steal sensitive employee and applicant data, while also defacing the FBI Jobs site. #ShinyHunters #OraclePeopleSoft #FBI
ShinyHunters Claims FBI Hack, Data Theft In PeopleSoft Zero-day Breach
ShinyHunters claims it breached FBI systems by exploiting an unpatched Oracle PeopleSoft zero-day, then moved into FBI-managed AWS GovCloud infrastructure and stole sensitive employee and applicant data. The group also says it defaced the FBI Jobs site, targeted additional organizations with the same flaw, and framed the intrusion as retaliation over an FBI FLASH report. #ShinyHunters #OraclePeopleSoft #FBI #AWSGovCloud #KashPatel
www.hendryadrian.com
September 22, 2026 at 8:30 PM
Google says UNC6240 and ShinyHunters-linked actors are exploiting Oracle PeopleSoft CVE-2026-35273, bypassing WAFs with an encoded path, dropping web shells, and stealing data from global sectors. #OraclePeopleSoft #ShinyHunters #FBIJobsGov
Attackers Bypass WAFs To Exploit Oracle PeopleSoft Flaw And Deploy Web Shells
Google says UNC6240 and ShinyHunters-linked activity are driving renewed mass exploitation of Oracle PeopleSoft flaw CVE-2026-35273, with attackers bypassing WAF controls, dropping web shells, and stealing data across multiple global sectors. The campaign has affected higher education, healthcare, government, technology, and other organizations, while separate ShinyHunters claims mention a breach of...
www.hendryadrian.com
September 27, 2026 at 1:00 AM
📢 ShinyHunters revendique le piratage du FBI via une zero-day Oracle PeopleSoft

Le groupe de cybercriminels ShinyHunters revendique publiquement une intrusion dans plusieurs services liés au FBI, affirmant détenir des données sur…

🟢 vérification factuelle haute
#FBI #OraclePeopleSoft #Cyberveille
ShinyHunters revendique le piratage du FBI via une zero-day Oracle PeopleSoft
Le groupe de cybercriminels ShinyHunters revendique publiquement une intrusion dans plusieurs services liés au FBI, affirmant détenir des données sur l'ensemble des employés et candidats du FBI. Selon un représentant du groupe, l'attaque a été réalisée via une vulnérabilité zero-day dans Oracle PeopleSoft.
cyberveille.ch
September 25, 2026 at 12:30 PM
📰 NAIC: Data yang Dicuri ShinyHunters dari Oracle PeopleSoft Hanya Berisi Informasi Publik

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/06/30/shinyhunters-peoplesoft-naic-data-publik/

#aws
##aws2#cve35273 #cyber#cybersecurityB#dataBreachl#oraclel#oraclePeoplesoftl#peoplesofto#ransomw
June 30, 2026 at 3:45 AM
📰 Nissan Ungkap Kebocoran Data Karyawan Akibat Serangan Zero-Day Oracle PeopleSoft

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/06/30/nissan-kebocoran-data-karyawan-oracle-peoplesoft/

#cve
-2#cve35273 #cyber#cybersecurityB#dataBreacha#nissanl#oraclel#oraclePeoplesoftl#peoplesoft#rans
June 30, 2026 at 3:46 AM
U.S. export controls forced Anthropic to restrict Fable 5 and Mythos 5 access for foreign nationals, while Chinese-linked actors and Arch Linux AUR hijacks fueled stealthy auth theft and rootkits. #Anthropic #China #Linux
Cybersecurity News | Daily Recap [13 Jun 2026]
Daily Recap, U.S. export controls compelled Anthropic to take Fable 5 and Mythos 5 offline for foreign nationals, underscoring tighter access to advanced AI models. Elsewhere, Chinese-linked actors showed long-running stealth in an authentication hijack and Linux backdoor campaigns, while Arch Linux AUR package hijacking pushed an infostealer and eBPF rootkit. #Anthropic #Fable5 #Mythos5 #Fable5 #Mythos5 #AuthHijack #LinuxBackdoor #ArchLinuxAUR #eBPF #Conti #ShinyHunters #OraclePeopleSoft #Coupang #23andMe #phpBB #FISA #DeepfakePornSite
www.hendryadrian.com
June 14, 2026 at 6:45 PM
Nissan confirmed a data breach tied to an Oracle PeopleSoft zero-day, with employee records possibly exposed across the US, Canada, Mexico, and Brazil. #Nissan #OraclePeopleSoft #Brazil
Nissan Employee Data Breached in Oracle PeopleSoft Hack
Nissan has confirmed a data breach tied to a zero-day campaign against Oracle PeopleSoft customers, with attackers suspected of stealing employee records across the US, Canada, Mexico, and Brazil. The campaign is widely linked to ShinyHunters, and other known targets include the University of Nottingham, the NAIC, Illinois Central College, and...
www.hendryadrian.com
June 30, 2026 at 12:15 PM
Nissan disclosed a breach after attackers used an Oracle PeopleSoft zero-day, exposing current and former employee data, including contact, banking, SSN, and tax details. #Nissan #Oracle #UnitedStates
Nissan discloses employee data breach linked to Oracle zero-day attacks
Nissan says a data breach exposed current and former employee information after attackers exploited an Oracle PeopleSoft vulnerability in theft attacks linked to ShinyHunters. The incident may have affected employees in the United States, Canada, Mexico, and Brazil, while Oracle and Mandiant have confirmed widespread exploitation of CVE-2026-35273 across hundreds of organizations. #Nissan #OraclePeopleSoft #ShinyHunters #CVE-2026-35273
www.hendryadrian.com
June 30, 2026 at 12:00 AM
NAIC says ShinyHunters used an Oracle PeopleSoft zero-day, but only public reports, outdated logs, and config files were taken. No PII or financial data was exposed. #NAIC #ShinyHunters #OraclePeopleSoft
NAIC says public data stolen in ShinyHunters' PeopleSoft breach
NAIC says ShinyHunters accessed its systems through an Oracle PeopleSoft zero-day, but the stolen data was limited to publicly available reports, outdated logs, and configuration files. The organization says no PII or financial data was exposed, and it has remediated affected systems after the extortion attempt and leak. #ShinyHunters #NAIC #OraclePeopleSoft #CVE-2026-35273
www.hendryadrian.com
June 29, 2026 at 11:45 PM
ShinyHunters is extorting universities after exploiting Oracle PeopleSoft zero-day CVE-2026-35273, potentially breaching 100+ organizations. Student data theft has been confirmed at the University of Nottingham. #ShinyHunters #OraclePeopleSoft
ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw
Researchers say ShinyHunters exploited an Oracle PeopleSoft zero-day, CVE-2026-35273, to potentially breach more than 100 organizations, with higher education accounting for most of the exposed victims. Oracle has issued mitigation guidance but no patch yet, while victims such as the University of Nottingham have confirmed student data theft. #ShinyHunters #OraclePeopleSoft #CVE-2026-35273 #UniversityofNottingham
www.hendryadrian.com
June 12, 2026 at 6:45 PM
ShinyHunters, tracked as UNC6240, exploited a zero-day in Oracle PeopleSoft Environment Management Hub endpoints, using MeshCentral staging and fake Azure binaries to steal data and extort education targets. #ShinyHunters #OraclePeopleSoft
ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit | Google Cloud Blog
Mandiant and GTIG identified an active extortion campaign by UNC6240 (ShinyHunters) exploiting CVE-2026-35273 as a zero-day against Oracle PeopleSoft Environment Management Hub endpoints. The attackers used MeshCentral staging servers, masquerading Azure-related binaries, and a propagation script to move laterally and leak stolen data to the ShinyHunters Data Leak Site. #UNC6240 #ShinyHunters #OraclePeopleSoft #CVE-2026-35273 #MeshCentral
www.hendryadrian.com
June 12, 2026 at 11:00 AM
Mandiant and GTIG linked UNC6240, aka ShinyHunters, to a May-June extortion campaign using a zero-day in Oracle PeopleSoft to hit Environment Management Hub endpoints and leak stolen data. #ShinyHunters #OraclePeopleSoft #EducationSector
ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit
Mandiant and GTIG attributed an active extortion and compromise campaign against Oracle PeopleSoft infrastructure to UNC6240 (ShinyHunters), using CVE-2026-35273 as a zero-day to target Environment Management Hub endpoints. The attackers used MeshCentral staging servers, custom propagation scripts, and data theft that culminated in leaks on the ShinyHunters Data Leak Site. #UNC6240 #ShinyHunters #OraclePeopleSoft #CVE-2026-35273 #MeshCentral #PSEMHUB
www.hendryadrian.com
June 12, 2026 at 3:42 AM
ShinyHunters is hitting Oracle PeopleSoft servers in ongoing data theft attacks, claiming theft from 300 instances across 100+ organizations. Nottingham University has confirmed a cybersecurity incident. #ShinyHunters #OraclePeopleSoft
Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks
Oracle PeopleSoft servers are being hit by ongoing data theft attacks linked to the ShinyHunters extortion gang, which claims to have stolen data from more than 100 organizations and 300 instances. Investigators found exposed tooling and indicators tied to the campaign, including scripts, staging files, and IP addresses, while Nottingham University has acknowledged a cybersecurity incident. #ShinyHunters #OraclePeopleSoft #NottinghamUniversity
www.hendryadrian.com
June 10, 2026 at 8:45 PM
保险监管机构NAIC遭到Oracle PeopleSoft黑客攻击,3.1TB数据被盗

保险监管机构NAIC遭OraclePeopleSoft漏洞攻击,3.1TB数据被盗。影响范围及后果待明确。

#NAIC #Oracle #网络安全 #数据泄露 #黑客攻击 #BreakingNewsUSA

Full story: https://jqjo.com/article/ey92h91h
July 1, 2026 at 10:15 AM
ShinyHunters Exploits Oracle PeopleSoft Zero-Day CVE-2026-35273 — 100+ Organizations Breached

https://blindthoughts.com/shinyhunters-oracle-peoplesoft-zero-day-cve-2026-35273

#oraclepeoplesoft #zeroday #shinyhunters #activeexploitation #databreach
June 12, 2026 at 10:16 AM