ShinyHunters Exploits Oracle PeopleSoft Zero-Day CVE-2026-35273

Élevé · The Hacker News ·

Exploité

Vérification: The item is future-dated and cites an unverifiable CVE, so it does not support a confirmed real security event.

En bref

  • ShinyHunters weaponized CVE-2026-35273, a zero-day in Oracle PeopleSoft.
  • Attackers bypass Google WAFs and achieve unauthenticated remote code execution.
  • Web shells are deployed globally across multiple sectors.
  • Mass exploitation observed in September 2026.

In September 2026, a threat group known as ShinyHunters launched a worldwide exploitation campaign targeting Oracle PeopleSoft. They leveraged a previously unknown vulnerability, tracked as CVE-2026-35273, to achieve remote code execution without needing authentication. This zero-day flaw allowed attackers to bypass web application firewalls, including those from Google, and then install web shells on compromised systems.

The impact is broad: multiple industries and regions have been affected. Because the flaw is unauthenticated, any exposed PeopleSoft instance could be at risk. The attackers' ability to evade WAF protections means traditional perimeter defenses may not block the initial intrusion. Once a web shell is in place, attackers can maintain persistent access, move laterally, and exfiltrate data.

Why this matters: Oracle PeopleSoft is widely used for HR, finance, and student information systems, including in government and education. A successful RCE can lead to data breaches, ransomware deployment, or full network compromise. The global scale and mass exploitation suggest a coordinated, opportunistic campaign rather than a targeted attack.

Context: ShinyHunters has a history of high-profile data theft and extortion. The use of a zero-day against a major enterprise application underscores the need for rapid patching and compensating controls. Google's WAF, while robust, was bypassed, indicating that signature-based defenses alone are insufficient.

What to watch: Oracle is expected to release a patch; until then, organizations should monitor for unusual web shell activity, restrict access to PeopleSoft interfaces, and apply virtual patching if available. Security teams should also review logs for exploitation attempts and consider threat hunting for indicators of compromise.

À faire maintenant

  1. Immediately isolate or restrict internet-facing PeopleSoft instances until a patch is available.
  2. Apply Oracle's emergency patch for CVE-2026-35273 as soon as it is released.
  3. Enable enhanced logging and monitoring for web shell indicators, especially in PeopleSoft directories.
  4. Review WAF rules and consider additional custom rules to detect exploitation attempts.
  5. Conduct a compromise assessment: scan for web shells, unusual processes, and outbound connections.
  6. Enforce least privilege and network segmentation to limit lateral movement.
  7. Subscribe to Oracle and Google security advisories for updates.

Références CVE

  • CVE-2026-35273

Source originale

The Hacker News

Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.

← Toute la veille cyber