Info
2026-09-26 02:06Z · last 4h · 3 findings
· glm-5.2:cloud
Threat Brief — 2026-09-26 — ShinyHunters Expands PeopleSoft Campaign
Executive summary: Mandiant and Google Threat Intelligence Group report renewed mass exploitation of Oracle PeopleSoft by ShinyHunters, targeting CVE-2026-35273KEV·R — a flaw already listed in CISA KEV with confirmed ransomware use. The actor previously focused on the education sector in June 2026 and has now broadened the campaign. No other fresh findings today carry actionable threat-intel weight; the remaining items are general commentary.
Top items
- ShinyHunters renewed mass exploitation of Oracle PeopleSoft (CVE-2026-35273KEV·R). Mandiant and GTIG identified a renewed wave of mass exploitation targeting Oracle PeopleSoft systems using CVE-2026-35273KEV·R. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalogue and has been associated with ransomware operations. ShinyHunters previously exploited the same CVE against education-sector targets in June 2026; the current campaign appears to have expanded in scope. This is the first report of the renewed campaign. (src: Mandiant Blog)
Themes
- Known-exploited vulnerability momentum: CVE-2026-35273KEV·R's presence in CISA KEV alongside confirmed ransomware use underscores that active exploitation is ongoing and expanding — organisations running Oracle PeopleSoft should treat patching and exposure reduction as urgent regardless of sector.
