chiprook
← Security
SecuritySeptember 28, 2026, 17:56

Google warns of new ShinyHunters campaign against Oracle PeopleSoft

Mandiant and GTIG warned of a fresh mass-exploitation campaign by ShinyHunters (UNC6240) targeting Oracle PeopleSoft customers. Attackers bypass WAF rules using the URL-encoded '%50' for 'P' in the /PSEMHUB path, deploying web shells and the SideEye backdoor. In June the group hit over 100 PeopleSoft customers, including Nissan and NAIC.

Google warns of new ShinyHunters campaign against Oracle PeopleSoft
#Google#Oracle#PeopleSoft#ShinyHunters
Read next
Security

Google: ShinyHunters renews mass exploitation of Oracle PeopleSoft flaw

Security

ShinyHunters claims FBI personnel data theft via Oracle PeopleSoft zero-day

Security

ShinyHunters hijacks Cl0p ransomware site, demands extortion payment

Policy

UK campaigners who beat AI copyright plan warn Australia