ShinyHunters reportedly exploits Oracle PeopleSoft flaw by bypassing firewall rules
IntCyberDigest, citing Google, reports web shells on dozens of systems worldwide, with the campaign spanning universities, healthcare, government, tech and transportation.
TLDR
IntCyberDigest reported on September 25 that, according to Google, ShinyHunters was mass-exploiting Oracle PeopleSoft vulnerability CVE-2026-35273 by bypassing firewall rules companies had relied on instead of patching. The account describes web shells on dozens of systems worldwide and a new backdoor called SIDEEYE on some servers, hidden inside a booby-trapped media player installer signed with a valid certificate. It also says Google published indicators of compromise, file hashes and a fix-it guide, and warned victims to prepare for extortion.
