ShinyHunters Exploits Oracle PeopleSoft Flaw to Plant SIDEEYE Backdoor

Moyen · Hackread ·

En bref

  • ShinyHunters is exploiting CVE-2026-35273 in Oracle PeopleSoft.
  • Attack chain includes WAF evasion, web shell placement, and SIDEEYE backdoor propagation.
  • Education and government PeopleSoft deployments should treat exposed instances as high risk.
  • Patch, hunt for webshells, rotate credentials, and monitor for SIDEEYE persistence.

ShinyHunters has been tied to active abuse of CVE-2026-35273, a medium-severity Oracle PeopleSoft vulnerability. According to the available facts, the intrusion path includes evading web application firewalls, placing web shells, and distributing the SIDEEYE backdoor. That combination gives attackers a durable foothold rather than a one-time compromise.

Any organization exposing a vulnerable PeopleSoft instance is in scope, but education agencies and government departments face elevated risk because these platforms often support administrative, financial, and student-related workflows. A single unpatched endpoint can become a staging point for deeper network access.

The WAF bypass is especially important: perimeter filtering alone will not stop this chain. Web shells provide interactive control, while SIDEEYE supplies persistence and potential lateral movement. Even a medium-rated CVE can cause severe operational and privacy consequences once post-exploitation begins.

For K-12 IT teams, the immediate priority is to determine whether PeopleSoft is internet-facing, whether the patch for CVE-2026-35273 is applied, and whether any unexpected files or processes exist on the application servers. Review logs for suspicious requests, new scripts, and outbound connections that do not match normal integrations.

Watch for vendor guidance, indicators of compromise, and reports of SIDEEYE activity in education or government networks. Treat this as an active campaign: validate backups, restrict unnecessary exposure, and be ready to isolate affected systems while preserving evidence.

À faire maintenant

  1. Apply Oracle's patch for CVE-2026-35273 immediately; if unavailable, isolate or restrict access to PeopleSoft.
  2. Search PeopleSoft web roots and upload directories for unexpected scripts, web shells, and SIDEEYE artifacts.
  3. Review WAF and web logs for evasion patterns, unusual POSTs, and requests targeting the vulnerable component.
  4. Rotate credentials and secrets for PeopleSoft service accounts, database links, and integration users.
  5. Enable enhanced logging and alerting on new processes, outbound C2-like traffic, and persistence mechanisms.
  6. Segment PeopleSoft servers from flat networks and limit outbound access to required destinations.
  7. Brief IT and security staff on the campaign and validate backups before remediation.

Références CVE

  • CVE-2026-35273

Source originale

Hackread

Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.

← Toute la veille cyber