RestonShinyHunters restarted attacks by exploiting PeopleSoft’s patch workaround itself.
PeopleSoft runs human resources and payroll worldwide, where the published workaround alone doesn’t stop this.
Mandiant said the group now targets organizations that applied only the published workaround for CVE-2026-35273, hitting dozens of systems.
Mandiant urges reviewing personnel logs, as ShinyHunters — behind last week’s FBI breach — says it won’t publish that data.
How each outlet framed it
- The Record
- reports ShinyHunters adapted tactics to target workarounds-not-patches, demonstrating threat-actor sophistication
- 404 Media leans critical
- reports ShinyHunters claims non-publication of FBI data but emphasizes remaining counterintelligence threat despite pledge
Sources: The Record, 404 Media