Internet-Facing PeopleSoft Console Becomes Extortion Foothold

An exposed PeopleSoft management console is not a small app bug. Once attackers can run commands there without logging in, they get a trusted admin channel into the environment, which is enough for reconnaissance, lateral movement, and extortion. Google Threat Intelligence Group and Mandiant say ShinyHunters used a zero-day, CVE-2026-35273, against Oracle PeopleSoft Environment Management before Oracle had patches out. FortiGuard says the campaign hit mostly higher-education victims, with about 68% of identified targets in education, and the post-compromise activity included remote admin tooling, data theft, and extortion. The blast radius is the managed environment, not the single server. If an admin layer is internet-facing, patching the web app alone does not remove the trust an attacker can abuse once they are inside.

Part of the PlainSec briefing for 2026-06-25

Sources