IntelliOS Threat Intel Operating System
IntelliOSPANDAModule|AIFlash Threat Intel Brief

ShinyHunters Oracle PeopleSoft Exploitation

CVE-2026-35273 Zero-Day Exploitation, Enterprise-App Trust, and Evidence-Led Response

Active exploitationCISA KEVCVSS 9.8Data theft and extortion
Published
Aug 9, 2026
Brief Version
v1.0
Updated
Aug 9, 2026
AI Monitor
Card Library review queue
Brief ID
PANDA-FTIB-PEOPLESOFT-2026-001
Template
Flash Threat Brief v2.0
  • Treat this as a compromise-assessment event: The campaign exploited CVE-2026-35273 as a zero-day from May 27 through June 9, and CISA later added it to KEV. Any affected system reachable during that period requires patch verification plus historical hunting; a current patch alone cannot resolve prior access.1, 2, 3
  • Reduce the exposed administrative surface immediately: Oracle requires its mitigation, while GTIG recommends disabling EMHub or removing PSEMHUB where appropriate and otherwise blocking external access to /PSEMHUB/* and /PSIGW/HttpListeningConnector. WAF body inspection alone is insufficient.1, 2
  • Hunt with exact campaign evidence: Correlate five staging IPs, azurenetfiles.net and its WebSocket endpoint, four staged agent names and hashes, the fanout script and marker filename, suspicious endpoint POSTs, unexpected JSP/XML files, outbound SMB, MeshCentral commands, SSH spraying, and zstd archives.1
  • Assume enterprise-app trust may extend beyond one host: PeopleSoft can expose HR, payroll, finance, student, identity, storage, integration, and administrative workflows. If compromise is plausible, scope connected credentials, shares, databases, exports, service accounts, and dependent parties before restoring trust.1, 7, 8
  • Keep impact statements evidence-specific: GTIG's >100 notifications and 68% education concentration describe potentially vulnerable endpoints, not confirmed victims. NAIC confirms access but disputes the actor's claimed volume. Separate exposure, compromise, acquisition, publication, and extortion claims.1, 7
  • Make SMB, MSP, legal, and insurance decisions per tenant: Record which data and services each relationship exposes, preserve evidence, notify providers, evaluate contractual and regulatory duties, and obtain written closure. Do not translate a shared provider's fleet status into a customer-specific impact claim.1, 3, 7

Research and scoping note

Current uncertainty remains material: public sources do not enumerate every victim, every exploit request, victim-specific agent identifiers, the contents of stolen archives, or exact Oracle patch-level numbers. Those gaps increase the importance of local telemetry and Oracle support records; they do not reduce urgency.1, 2, 3, 4

Mandiant and GTIG identified an active compromise and extortion campaign attributed to UNC6240, which they associate with ShinyHunters, targeting Oracle PeopleSoft application infrastructure. Observed activity ran from May 27 through June 9 and aligned directly with exploitation of PSEMHUB endpoints. Because Oracle disclosed CVE-2026-35273 on June 10, this was zero-day exploitation.1, 2

Oracle describes a remotely exploitable, unauthenticated HTTP vulnerability in Updates Environment Management that can result in PeopleTools takeover and remote code execution. Supported affected releases are 8.61 and 8.62; Oracle warns earlier unsupported releases are likely affected but were not tested. CVSS 3.1 is 9.8 with high confidentiality, integrity, and availability impacts.2, 4

CISA added the issue to KEV on June 12 with a June 15 due date and requires vendor mitigation plus applicable BOD 26-04 forensic triage. The catalog's known-ransomware field is Known; this supports extortion/ransomware risk prioritization but does not prove encryption, identify every actor, or establish a local incident.3, 4

GTIG notified more than 100 organizations whose IPs correlated with potentially vulnerable endpoints; most were U.S.-based and 68% were higher-education institutions. These are exposure notifications, not a confirmed victim count. GTIG says some recipients blocked or remediated activity, while others experienced compromise and publication of stolen data.1

The public campaign record is technically concrete. Five sequential staging IPs served attacker directories on TCP 8888. Customized MeshCentral agents masqueraded as Azure services and connected to wss://azurenetfiles.net:443/agent.ashx. Operators inspected PeopleSoft and WebLogic configuration, deployed a victim-specific fanout script, sprayed SSH credentials, placed an extortion marker, compressed exfiltrated data with zstd, and connected to 176.120.22.24, the public leak-site mirror.1

Detection should combine exact IOCs with behavior: external POSTs to /PSEMHUB/hub and /PSIGW/HttpListeningConnector; loopback or internal SSRF values; unexpected JSPs below PSEMHUB.war; content in envmetadata/transactions; suspicious logs, persistantstorage, or scratchpad directories; recently changed XML below envmetadata/data/environment; outbound TCP 445; MeshCentral execution; sshpass; zstd; and the published filenames and hashes.1

Observed impact crosses enterprise boundaries. NAIC confirmed unauthorized PeopleSoft access and temporary access to certain data storage areas, but said it did not believe the actor held the claimed volume and had no confirmed public release as of June 23. That direct disclosure illustrates why leak-site claims, campaign attribution, and organization-confirmed impact must remain separate.7

For U.S. SMBs, PeopleSoft may be a hidden supply-chain exposure through payroll, benefits, universities, insurers, public-sector partners, MSPs, or shared administrative services. Leaders should request per-instance patch and investigation evidence, map data and credentials shared with providers, preserve contractual notices, and avoid assuming either safety or breach from provider-level statements alone.1, 7, 8

Immediate response is to apply Oracle's alert, reduce PSEMHUB/Integration Broker exposure, preserve evidence, search the full historical window, contain suspicious web tiers, rotate or revoke plausibly exposed trust, validate databases and exports, and rebuild or restore from trusted state when integrity cannot be established. No public fixed patch-level numbers replace Oracle's customer-specific patch documentation.1, 2, 3

Research and scoping note

The brief does not infer compromise from internet exposure, attribution from an IOC match, or data loss from a marker file. Conversely, absence of the published IOCs does not rule out exploitation because infrastructure and tooling can change. Use multiple corroborating signals and preserve negative as well as positive findings.1, 2, 3, 7