ShinyHunters restarted attacks by exploiting PeopleSoft’s patch workaround itself.

PeopleSoft runs human resources and payroll worldwide, where the published workaround alone doesn’t stop this.

Mandiant said the group now targets organizations that applied only the published workaround for CVE-2026-35273, hitting dozens of systems.

Mandiant urges reviewing personnel logs, as ShinyHunters — behind last week’s FBI breach — says it won’t publish that data.

How each outlet framed it
The Record
reports ShinyHunters adapted tactics to target workarounds-not-patches, demonstrating threat-actor sophistication
404 Media leans critical
reports ShinyHunters claims non-publication of FBI data but emphasizes remaining counterintelligence threat despite pledge

Sources: The Record, 404 Media