ShinyHunters hackers are going after Oracle systems once again - here's what we know

https://cdn.mos.cms.futurecdn.net/37uyEphcLreEFNUVCQzurn-2560-80.jpg
  • ShinyHunters bypass PeopleSoft mitigation rules, reviving exploitation of a critical zero-day vulnerability
  • The campaign has expanded globally, targeting organizations across technology, healthcare, government, and other sectors
  • Oracle’s original patch remains effective, while organizations should investigate systems and rotate potentially exposed credentials

ShinyHunters have found a way to bypass a mitigation for a zero-day they previously exploited - so now, not only are they back to abusing the same bug, they’ve even expanded their scope to target a much larger pool of organizations.

In June 2026, it was reported that ShinyHunters, the infamous data extortionists, found a Java deserialization vulnerability in Oracle’s PeopleSoft Environment Management Hub (PSEMHUB) servlet that allowed them to achieve web shell deployment or fileless command execution on vulnerable servers.

Oracle PeopleSoft is a suite of enterprise business softwareused mainly by large organizations, universities, governments, and corporations to manage things like human resources, finance, supply chain, and...

Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE

Read more

http://www.techmeme.com/img/techmeme_sq328.png

Tavus unveils Griffin, the “first Human Interaction Model”, which it says passed the “video Turing test”, with 48% of users thinking it was human in live chats

Sponsor Posts Subquadratic: the LLM built for 12M-token reasoning — SubQ can reason across entire codebases and document sets in one pass with no RAG workarounds. Read how SubQ 1.1 Small holds near-perfect retrieval out to 12M tokens. Introducing Campus: The digital home for educational institutions — Every educational institution needs