Oracle PeopleSoft RCE Flaw Used as Zero-Day in Ongoing ShinyHunters Campaign


Oracle PeopleSoft RCE Flaw Used as Zero-Day in Ongoing ShinyHunters Campaign

Pierluigi Paganini
June 12, 2026

ShinyHunters exploited a critical Oracle PeopleSoft zero-day to breach over 100 organizations, mostly universities, before a patch was available.

Mandiant and Google’s Threat Intelligence Group published an analysis of an active ShinyHunters campaign on June 11, one day after Oracle finally issued an advisory for the vulnerability being exploited. The gap matters: the activity ran from May 27 to June 9, meaning every organization hit during those two weeks was dealing with a zero-day, a flaw with no available patch and no official vendor warning. Sixty-eight percent of the more than 100 organizations Mandiant notified were universities and colleges, most of them in the United States.

The flaw, CVE-2026-35273 (CVSS score of 9.8), is a remote code execution vulnerability in Oracle PeopleSoft’s Environment Management component, rated 9.8 out of 10. No authentication required. No user interaction required. Just network access to the Environment Management Hub endpoint and you can take over the server.

“Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component.” reads the report published by Google. “The exploitation of this vulnerability directly aligns with the observed targeting of Environment Management Hub (PSEMHUB) endpoints. Because this activity predates Oracle’s June 10, 2026 advisory, the vulnerability was exploited as a zero-day.”

PeopleTools versions 8.61 and 8.62 are confirmed affected; Oracle says earlier unsupported versions are likely vulnerable too.

The attackers left their staging infrastructure exposed, which is how Mandiant got a detailed look at the operation. Researcher @nahamike01 publicly flagged open directories on five sequential IP addresses, all running Python’s built-in HTTP server on port 8888. Mandiant triaged all five and found a shared .bash_history file, identical across every host, that laid out the entire operation in timestamped detail. If you’re going to run a sophisticated zero-day campaign against universities, at least password-protect your file server.

“The staging infrastructure hosted pre-configured Windows MeshCentral agent binaries disguised as Microsoft Azure services, specifically named meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe.” reads the report. “Static analysis indicates these agents were hardcoded to establish communication with the command and control (C2) server wss://azurenetfiles.net:443/agent.ashx.”

The domain was chosen to look like Microsoft Azure NetApp Files. MeshCentral is legitimate open-source remote management software, which means the traffic blends into normal administrative activity and doesn’t trigger obvious alerts.

The command history tells the full operational story. On May 27 at 22:14 UTC, the attackers installed MeshCentral version 1.1.59. Eleven minutes later they installed acme-client to automate Let’s Encrypt SSL certificate provisioning for azurenetfiles.net, giving their C2 a valid certificate. They then used MeshCentral’s CLI tool meshctrl.js to run commands on compromised endpoints: mapping Oracle PeopleSoft configurations, reading process scheduler config files, parsing internal host tables, and inspecting WebLogic XML configs to identify additional targets inside each victim network.

Attackers performed lateral movement through a script named [victim_abbreviation]_fanout.sh, written directly to /tmp on compromised hosts and executed remotely via MeshCentral. The script parses /etc/hosts for internal PeopleSoft node hostnames, then sprays a hardcoded list of usernames and passwords against each one over SSH. On successful login it copies a file named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT into WebLogic and Process Scheduler directories, both as an extortion marker and as a propagation confirmation the operators could verify remotely.

Exfiltration went out compressed with zstd, followed by an outbound SSH connection to 176.120.22.24, the IP hosting the public mirror of the ShinyHunters data leak site.

The University of Nottingham is among the first confirmed victims. Have I Been Pwned has indexed approximately 455,000 unique email addresses from the leaked data, covering current students and alumni, with names, addresses, phone numbers, passport numbers, and records on ethnicity and disabilities. ShinyHunters has said that victim outreach has only just started and most compromised organizations haven’t been posted yet.

For any organization running Oracle PeopleSoft right now, the immediate priority is isolation. Oracle’s guidance is to disable the Environment Management Hub service entirely on multi-server setups, or remove the PSEMHUB application on single-server setups. If neither is possible, block external access to /PSEMHUB/* and /PSIGW/HttpListeningConnector at the perimeter.

Endpoint Access Restrictions: If you cannot disable the EMHub Service, immediately block external network access to the sensitive endpoints /PSEMHUB/* (specifically /PSEMHUB/hub) and /PSIGW/HttpListeningConnector at the network perimeter or firewall level. Relying solely on Web Application Firewall (WAF) body-inspection rules is insufficient, as these controls can be bypassed.” concludes the report.

Restricting these endpoints doesn’t break normal user sessions; EMHub and the Integration Broker Listening Connector are administrative components, not user-facing ones. Then hunt: check WebLogic access logs for external POST requests to those paths, scan for unexpected JSP files under the PSEMHUB.war directory, look for directories named logs, persistantstorage, or scratchpad under PSEMHUB paths, and monitor for outbound SMB traffic on port 445 from PeopleSoft hosts to external destinations.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, ShinyHunters)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Digital marketing changes fast. One minute a platform is hot, the next it’s outdated. Consumer habits shift quickly, and the strategies that worked last year might not work today. If you’re trying to stay relevant in this ever-evolving field, the big question is: how can you level up your skills without going back to school?

Whether you’re brand-new to marketing or a traditional marketer moving into digital, here are seven practical (and proven) ways to sharpen your skills, no formal degree required.

1. Take Online Courses That Actually Teach You Something

Not all online courses are equal. The best ones are built by marketers who actually do this stuff every day not just teach theory. These courses blend hands-on learning with real-world projects that help you build skills employers care about.

What to look for:

  • Instructors with real industry experience
  • Projects based on actual campaigns
  • Updated content that reflects current tools and platforms
  • Certifications that carry weight on your resume

Recommended platforms: Google Skillshop, HubSpot Academy, and LinkedIn Learning are all great places to start.

2. Learn from the Pros in the Industry

Want to know what’s working in digital marketing right now? Follow the experts who are already doing it. They share not just tactics but also insights into the strategy behind successful campaigns. If your goal is to become an SEO expert in Nepal, seek out local professionals who are ranking well or leading agencies you’ll gain insights that are specific to your market.

How to get the most from them:

  • Follow a mix of global and local thought leaders
  • Subscribe to their newsletters and podcasts
  • Ask questions and engage with their content
  • Join their webinars or virtual events

Tip: Pick experts in areas you want to master—SEO, social media, email marketing, or AI tools.

3. Use Free Resources to Explore and Learn

You don’t always have to pay to learn. There’s a ton of free, high-quality content online that covers everything from the basics to advanced strategies.

Top free resources to check out:

  • Coursera & edX: Free courses from top universities
  • Google Digital Garage: Solid fundamentals in digital marketing
  • YouTube: Tutorials, breakdowns, and real case studies
  • Blogs: Keep up with Moz, Search Engine Journal, and Content Marketing Institute

4. Get Hands-On with Personal Projects

Reading is helpful, but doing is where the real learning happens. Try testing strategies on a personal blog, passion project, or fictional brand.

Simple project ideas:

  • Start a blog and learn SEO by optimizing your posts
  • Run a small Instagram or Facebook campaign
  • Build an email list for a hobby or passion project
  • Try a basic Google Ads campaign with a tiny budget

5. Join Online Communities and Connect with Others

One of the best parts of digital marketing is the community. There are countless online (and offline) spaces where marketers help each other grow.

Where to find them:

  • LinkedIn groups: Look for niche-focused communities
  • Reddit: r/digitalmarketing, r/SEO, and r/PPC are packed with advice
  • Slack groups: Many cities and marketing niches have active ones
  • Local events: Don’t underestimate the power of in-person networking

6. Get Certified (It’s Worth It)

Certifications show that you’ve taken the time to learn and understand the tools. They’re especially helpful if you’re transitioning from another field or just getting started.

Top certifications to consider:

  • Google Ads & Google Analytics
  • HubSpot Inbound Marketing
  • Meta (Facebook) Social Media Marketing
  • Salesforce Marketing Cloud (for advanced roles)

7. Analyze Real Marketing Data

Looking at real-world data helps you understand what works—and what doesn’t. Try working with small businesses or nonprofits to get your hands on real campaign results.

Where to find real data opportunities:

  • Help a local business improve their online presence
  • Volunteer for a nonprofit’s marketing team
  • Freelance on small gigs to build a portfolio
  • Ask your employer to let you assist on a digital campaign

The Skills That Will Make You Stand Out

To be great at digital marketing, you need a mix of creative and analytical abilities. The top marketers are flexible, data-savvy, and constantly learning.

Here’s what to focus on:

  • Analytics: Know how to read and act on data
  • Writing and content: Craft messages that get attention and convert
  • Tech skills: A basic understanding of HTML, email tools, and CRMs
  • Strategy: Know how to align marketing goals with business objectives
  • Adaptability: Be ready to pivot with new trends and tools

Start Small, Learn Fast

You don’t need a fancy degree to break into or level up in digital marketing. What you need is consistency, curiosity, and a bit of creativity. Pick one or two of the strategies above that fit your style, and commit to them for the next month.

Most importantly, don’t just learn—apply. Watch a course, then launch a mini-campaign. Read a blog, then try out the strategy on your own site. Digital marketing rewards action, not just knowledge.



Source link