# Google Warns of ShinyHunters' Fresh Oracle PeopleSoft Campaign

DevFeed: [Google Warns of ShinyHunters' Fresh Oracle PeopleSoft Campaign](<https://devfeed.tech/articles/google-warns-of-shinyhunters-fresh-oracle-peoplesoft-campaign-61039.md>)

Original publisher: [Read original article](<https://www.securityweek.com/google-warns-of-shinyhunters-fresh-oracle-peoplesoft-campaign/>)

Author: Ionut Arghire

Published: 2026-09-28T10:56:46Z

Content type: news

Language: en

Sources: [SecurityWeek](<https://devfeed.tech/sources/securityweek.md>)

Topics: [CVE-2026-25544](<https://devfeed.tech/topics/cve-2026-25544.md>), [exploit chaining](<https://devfeed.tech/topics/exploit-chaining.md>), [Wagtail](<https://devfeed.tech/topics/wagtail.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [cve-2026-35273](<https://devfeed.tech/tags/cve-2026-35273.md>), [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [featured](<https://devfeed.tech/tags/featured.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [google](<https://devfeed.tech/tags/google.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [http](<https://devfeed.tech/tags/http.md>), [load](<https://devfeed.tech/tags/load.md>), [node](<https://devfeed.tech/tags/node.md>), [oracle-peoplesoft](<https://devfeed.tech/tags/oracle-peoplesoft.md>), [peoplesoft](<https://devfeed.tech/tags/peoplesoft.md>), [proxy](<https://devfeed.tech/tags/proxy.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [request-path](<https://devfeed.tech/tags/request-path.md>), [shinyhunters](<https://devfeed.tech/tags/shinyhunters.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

Google and Mandiant report that ShinyHunters modified an exploit for the PeopleSoft vulnerability CVE-2026-35273 to bypass web application firewall rules and attack additional organizations. The campaign uses URL encoding in requests to reach a vulnerable endpoint and deploy web shells; the reported activity may reflect the modified exploit rather than a new zero-day.

## Source excerpt

The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273. The post Google Warns of ShinyHunters' Fresh Oracle PeopleSoft Campaign appeared first on SecurityWeek.