ADVERTISEMENT

ShinyHunters targeting Oracle zero-day days after FBI attack, Google warns

A new ShinyHunters campaign is bypassing firewall defenses and deploying a newly discovered backdoor – is this how they breached the FBI?

Oracle cloud bug allowed accessing other users’ virtual disks
Stefanie Schappert
Stefanie Schappert Senior Journalist
September 26, 2026 Updated: 40 seconds ago 2 min read
Key takeaways:

ShinyHunters bypasses firewall defenses

We observed a consistent sequence of events in targeted PeopleSoft environments, progressing from discovery and verification to web shell deployment and hands-on-keyboard activity,
– Google Threat Intelligence Group

Connected to FBI attacks?

ADVERTISEMENT
SHFBI
ShinyHunters claims the FBI as its latest victim on its leak site. Image by Cybernews

New SIDEEYE backdoor found in attacks

Hacker Windows
ShinyHunters is deploying the SIDEEYE backdoor on compromised Windows PeopleSoft servers, Google researchers warn. Image by Cybernews
  • Patch CVE-2026-35273 now
  • Inspect PeopleSoft servers for the web shells/backdoor
  • Rotate exposed credentials
  • Hunt for the campaign's network indicators
Stefanie Schappert
Senior Journalist
ADVERTISEMENT