WorkThe story, in brief

ShinyHunters’ exploitation of a new PeopleSoft zero-day hole threatens to change enterprise risk dynamics

PeopleSoft shops face a potentially unpatched zero-day with no vendor guidance. Here's what enterprise security teams should do now.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

A claimed new PeopleSoft preauth RCE zero-day, allegedly used by ShinyHunters against FBI systems and Fortune 500 targets, exposes a pattern of critical flaws in Oracle's enterprise software. Unlike the June CVE, this one remains unacknowledged by Oracle, leaving customers without mitigation guidance while waiting for confirmation that may not come.

The key facts

17 to know
  1. ShinyHunters claims a new, distinct PeopleSoft preauth RCE zero-day separate from CVE-2026-35273 (June flaw)

  2. FBI confirmed breach of FBI employee data but did not disclose attack vector

  3. No CVE assigned; not on CISA Known Exploited Vulnerabilities catalog; Oracle has not commented

  4. Claimed to be actively exploited against unnamed Fortune 500 targets

  5. June PeopleSoft zero-day CVE-2026-35273: many organizations bypassed patching with WAF rules, which attackers defeated by encoding 'P' as '%50' in the URL path

  6. Frank Dickson (Dickson Research): recommends immediate removal of Environment Management Hub and Integration Broker from public internet; search logs for encoded PSEMHUB paths; implement Mandiant report recommendations from late September

  7. Philip Harris (IDC): cautioned that zero-day claim is from threat actor only, not independent forensic confirmation or Oracle acknowledgment

  8. Jeff Valdes (Acceligence): criticized Oracle's silence; customers need clarity on whether original guidance is sufficient, additional mitigations needed, and whether configurations materially increase exposure

  9. Suspected ShinyHunters member arrested by FBI (reported Saturday by Reuters); cooperating with law enforcement

  10. ShinyHunters claims exploitation of a new PeopleSoft preauth RCE zero-day, distinct from CVE-2026-35273 (June 2026)

  11. FBI breach of employee data confirmed by FBI; attack vector not disclosed by law enforcement

  12. Zero-day claim sourced only from threat actor; no CVE assigned, not on CISA Known Exploited Vulnerabilities catalog, Oracle has not commented

  13. Analyst Frank Dickson recommends: pull Environment Management Hub and Integration Broker from public internet, apply patch when available, search logs for encoded variants, rotate credentials if web shell detected

  14. IDC analyst Philip Harris notes pattern risk: if real, a second critical unpatched preauth RCE in same window suggests recurring exposure, not isolated bug

  15. Consultant Jeff Valdes criticizes Oracle silence: customers lack clarity on whether original guidance remains sufficient, additional mitigations needed, configuration risk increases

  16. Prior June 2026 PeopleSoft zero-day exploited by ShinyHunters; organizations mitigated with WAF rules, attackers bypassed by encoding single character ('%50' for 'P')

  17. FBI suspect arrested, cooperating with law enforcement; analysts downplay implications of single arrest given group's persistence

Go to the source

CIOcio.com

Publisher excerpt: A recent compromise of PeopleSoft by hacking group ShinyHunters is causing new concerns for enterprise users of the Oracle product, with analysts recommending extreme measures in response. Law enforcement has made some progress in its pursuit of the cyber criminals involved. On Saturday, Reuters…
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work