Oracle PeopleSoft RCE Flaw Used as Zero-Day in Ongoing ShinyHunters Campaign


Oracle PeopleSoft RCE Flaw Used as Zero-Day in Ongoing ShinyHunters Campaign

Pierluigi Paganini
June 12, 2026

ShinyHunters exploited a critical Oracle PeopleSoft zero-day to breach over 100 organizations, mostly universities, before a patch was available.

Mandiant and Google’s Threat Intelligence Group published an analysis of an active ShinyHunters campaign on June 11, one day after Oracle finally issued an advisory for the vulnerability being exploited. The gap matters: the activity ran from May 27 to June 9, meaning every organization hit during those two weeks was dealing with a zero-day, a flaw with no available patch and no official vendor warning. Sixty-eight percent of the more than 100 organizations Mandiant notified were universities and colleges, most of them in the United States.

The flaw, CVE-2026-35273 (CVSS score of 9.8), is a remote code execution vulnerability in Oracle PeopleSoft’s Environment Management component, rated 9.8 out of 10. No authentication required. No user interaction required. Just network access to the Environment Management Hub endpoint and you can take over the server.

“Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component.” reads the report published by Google. “The exploitation of this vulnerability directly aligns with the observed targeting of Environment Management Hub (PSEMHUB) endpoints. Because this activity predates Oracle’s June 10, 2026 advisory, the vulnerability was exploited as a zero-day.”

PeopleTools versions 8.61 and 8.62 are confirmed affected; Oracle says earlier unsupported versions are likely vulnerable too.

The attackers left their staging infrastructure exposed, which is how Mandiant got a detailed look at the operation. Researcher @nahamike01 publicly flagged open directories on five sequential IP addresses, all running Python’s built-in HTTP server on port 8888. Mandiant triaged all five and found a shared .bash_history file, identical across every host, that laid out the entire operation in timestamped detail. If you’re going to run a sophisticated zero-day campaign against universities, at least password-protect your file server.

“The staging infrastructure hosted pre-configured Windows MeshCentral agent binaries disguised as Microsoft Azure services, specifically named meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe.” reads the report. “Static analysis indicates these agents were hardcoded to establish communication with the command and control (C2) server wss://azurenetfiles.net:443/agent.ashx.”

The domain was chosen to look like Microsoft Azure NetApp Files. MeshCentral is legitimate open-source remote management software, which means the traffic blends into normal administrative activity and doesn’t trigger obvious alerts.

The command history tells the full operational story. On May 27 at 22:14 UTC, the attackers installed MeshCentral version 1.1.59. Eleven minutes later they installed acme-client to automate Let’s Encrypt SSL certificate provisioning for azurenetfiles.net, giving their C2 a valid certificate. They then used MeshCentral’s CLI tool meshctrl.js to run commands on compromised endpoints: mapping Oracle PeopleSoft configurations, reading process scheduler config files, parsing internal host tables, and inspecting WebLogic XML configs to identify additional targets inside each victim network.

Attackers performed lateral movement through a script named [victim_abbreviation]_fanout.sh, written directly to /tmp on compromised hosts and executed remotely via MeshCentral. The script parses /etc/hosts for internal PeopleSoft node hostnames, then sprays a hardcoded list of usernames and passwords against each one over SSH. On successful login it copies a file named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT into WebLogic and Process Scheduler directories, both as an extortion marker and as a propagation confirmation the operators could verify remotely.

Exfiltration went out compressed with zstd, followed by an outbound SSH connection to 176.120.22.24, the IP hosting the public mirror of the ShinyHunters data leak site.

The University of Nottingham is among the first confirmed victims. Have I Been Pwned has indexed approximately 455,000 unique email addresses from the leaked data, covering current students and alumni, with names, addresses, phone numbers, passport numbers, and records on ethnicity and disabilities. ShinyHunters has said that victim outreach has only just started and most compromised organizations haven’t been posted yet.

For any organization running Oracle PeopleSoft right now, the immediate priority is isolation. Oracle’s guidance is to disable the Environment Management Hub service entirely on multi-server setups, or remove the PSEMHUB application on single-server setups. If neither is possible, block external access to /PSEMHUB/* and /PSIGW/HttpListeningConnector at the perimeter.

Endpoint Access Restrictions: If you cannot disable the EMHub Service, immediately block external network access to the sensitive endpoints /PSEMHUB/* (specifically /PSEMHUB/hub) and /PSIGW/HttpListeningConnector at the network perimeter or firewall level. Relying solely on Web Application Firewall (WAF) body-inspection rules is insufficient, as these controls can be bypassed.” concludes the report.

Restricting these endpoints doesn’t break normal user sessions; EMHub and the Integration Broker Listening Connector are administrative components, not user-facing ones. Then hunt: check WebLogic access logs for external POST requests to those paths, scan for unexpected JSP files under the PSEMHUB.war directory, look for directories named logs, persistantstorage, or scratchpad under PSEMHUB paths, and monitor for outbound SMB traffic on port 445 from PeopleSoft hosts to external destinations.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, ShinyHunters)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


You’ve built your small business from the ground up. It’s your pride and joy, your financial security, and a potential legacy for your family. But what happens to your business interests after you’re gone? Without proper estate planning, your small business could face a chaotic future, disrupting operations, hurting employees, and jeopardizing your loved ones’ inheritance.

Business estate planning is your secret weapon. It’s not just for the ultra-wealthy with complex trusts and wills. For small business owners, it’s a crucial tool to ensure business continuity and protect your business value. Here’s how you can craft a comprehensive estate plan:

Know Your Business Inside and Out

The first step in your estate planning process is taking a deep dive into your business affairs. Make a list of all your business assets: equipment, inventory, intellectual property, and real estate.

Furthermore, don’t forget your business debts like loans and outstanding payments. This comprehensive list helps you understand what needs protecting and planning for in your estate planning documents.

Chart Your Business’s Future Course

What do you envision for your business after you’re gone? Should it stay in the family? Be sold to a trusted partner? Wind down entirely? This is where business succession planning comes in. It’s about deciding the future of your business in a way that honors your legacy and sets your team up for success.

Here are some questions to consider:

  • Family Business? Do you have a family member who shares your passion and has the skills to lead?
  • Trusted Partner? Is there a key employee you see as the ideal successor?
  • Time for a Change? Are you open to selling the business to ensure a smooth transition?

There’s no right or wrong answer. The key is to have open conversations with your loved ones and key employees to understand their goals and aspirations. This will guide you in crafting a business succession plan that feels right for everyone involved.

Develop a Rock-Solid Business Succession Plan

This plan outlines who will take over your business and how. You might identify a family member, a key employee, or even an outside buyer. The business succession plan should detail the transfer process, including training and timeline.

Here’s how to craft a plan as strong as your business itself:

  • Identify Your Successor: It could be a family member you’ve been mentoring, a trusted key employee, or even an outside buyer.
  • Groom Your Successor: Start by involving them in key decisions to give them opportunities to learn the ropes.
  • Plan for the Unexpected: Have a backup plan in place. Identifying another potential leader or outline a buy-out option for remaining partners.

An experienced estate planning attorney like Keele & Parke can help you draft a legally sound plan that considers state law and tax implications.

Avoid Conflict with Ironclad Sell Agreements

If you have co-owners, a sell agreement is vital. This agreement dictates what happens to a deceased or incapacitated owner’s share of the business. It prevents conflict among remaining partners and ensures a smooth ownership transition in your overall estate plan.

Wills vs. Trusts: Choosing the Right Tool

A will can designate who inherits your business assets. But the problem is it can be a slow and public process through probate court.

Here’s where a revocable living trust comes in. Think of it as a private vault that holds your business assets during your lifetime. You can name yourself as trustee, so you’re still in control.

Another thing, you can designate a successor trustee to seamlessly take over managing the business if you become disabled or pass away. This avoids probate and keeps things running smoothly for your loved ones and your employees.

Wills are still important for your overall estate plan, especially for personal assets outside the trust. But for your business, a revocable living trust offers flexibility, privacy, and peace of mind.

Minimize Estate Taxes Through Strategic Planning

Nobody wants a big chunk of their hard-earned business value going to the government after they’re gone. That’s where estate taxes come in, and they can be a real burden for your family. But don’t worry, there are smart estate planning strategies you can use to minimize the impact of these taxes.

  • Smart Business Structure: The legal entity you choose for your business can impact your estate taxes. Talk to your estate planning attorney about structuring your business as a limited liability company (LLC) or another entity that might offer tax advantages.
  • Explore Powerful Trusts: There are special types of trusts, like grantor retained annuity trusts (GRATs), that can be used to transfer ownership of your business interests to your heirs while minimizing the taxable value of those assets.

The right strategy for you will depend on your specific situation and goals. That’s why it’s crucial to work with an experienced estate planning attorney and financial advisor. They can help you create a personalized plan that minimizes your estate taxes and protects your legacy.

Don’t Neglect Your Personal Estate Plan

Your business is just one piece of the puzzle. You also need a personal estate plan that includes a will, power of attorney, and healthcare directives. Without it, your loved ones could face a legal mess during tough times. Bills might go unpaid, important decisions could be delayed, and family heirlooms could end up in the wrong hands.

An estate plan ensures your wishes are followed. It names guardians for your minor children, designates beneficiaries for your personal assets (like your home and savings), and appoints someone you trust to make healthcare decisions if you’re unable to. This gives your family peace of mind knowing they’re taken care of, even in your absence.

Life Insurance: A Lifeline for Your Loved Ones

A life insurance policy provides your beneficiaries with a lump sum of cash upon your death. This can be crucial for surviving family members or business partners, especially if they need to buy out another owner’s share through a sell agreement or pay estate taxes.

Regularly Review and Update Your Plan

Life circumstances change, and so should your estate plan. Regularly review your plan, especially after major life events like marriage, children, or changes in your business structure.

Seek Professional Guidance for a Comprehensive Plan

Business estate planning involves complex legal and financial considerations. Don’t try to go it alone. Consult with an experienced estate planning attorney specializing in business succession planning and a financial advisor with experience in small business matters. Their expertise can ensure your estate plan is comprehensive, legally sound, and achieves your goals for business continuity and protecting your loved ones.

Final Thoughts

Safeguarding your business is like protecting your family’s future. Take control. Schedule a consultation with an experienced estate planning attorney today. They’ll guide you through the process and ensure your legacy lives on.



Source link