# ShinyHunters expands PeopleSoft attacks with firewall bypass

_Published Friday, September 25, 2026 at 9:07 PM EDT · Security, Infrastructure · Latest · Tier 1 — Major_

![ShinyHunters expands PeopleSoft attacks with firewall bypass — Primary](https://storage.googleapis.com/gweb-cloudblog-publish/images/03_ThreatIntelligenceWebsiteBannerIdeas_BA.max-2600x2600.png)

Google's Mandiant and Threat Intelligence Group report a renewed ShinyHunters campaign exploiting an Oracle PeopleSoft flaw across several sectors. The attackers have placed web shells on dozens of systems globally, expanding beyond the academic institutions targeted in June.

The attackers changed the request path by encoding one character, allowing traffic to pass firewall rules that look for the literal path while PeopleSoft still routes it to the vulnerable component. Google says some targeted organizations had blocked that path but had not patched the flaw. It recommends applying Oracle's security alert and restricting access to the administrative service.

## Sources

- [Cloud Blog](https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft/)

---
Canonical: https://techandbusiness.org/newswire/tdIrTVIE45LMEb2tvizFP0
Published: 2026-09-26T01:07:29.899Z
Story chronology: 2026-09-25T14:00:00.000Z
Retrieved: 2026-09-26T03:05:37.683Z
Publisher: Tech & Business (techandbusiness.org)
