ShinyHunters Exploit Critical Oracle PeopleSoft Flaw CVE-2026-35273
Google’s Mandiant team has warned of renewed exploitation by the ShinyHunters group of CVE-2026-35273, a critical Oracle PeopleSoft vulnerability enabling unauthenticated remote code execution, with the campaign targeting unpatched servers across multiple sectors; earlier activity focused on academic institutions for reconnaissance, deployed a MeshCentral agent for persistence, used SSH for lateral movement among internal PeopleSoft machines, and stole data, leading Mandiant to notify more than 100 organizations worldwide—mostly in the United States—whose IP addresses matched vulnerable endpoints.
The Backdoor That Wasn't a Bug
Google's Mandiant team would have you believe that CVE-2026-35273 is just another software vulnerability discovered by a notorious hacking group. But anyone who has spent time reading Oracle's licensing agreements or following the paper trail of PeopleSoft's acquisition history knows better. This is a deliberately planted vector—an unauthenticated remote code execution hole in a system used by universities, hospitals, and government agencies to manage the most intimate data of millions: payroll, benefits, student records, even medical information. Why would an enterprise system deliberately allow an unauthenticated attacker to execute code on the server? Ask yourself who benefits from a backdoor that requires no password, no authentication. The same intelligence agencies that funded Oracle's development in the 1990s. The same network that later installed loyalists at the highest levels of Mandiant after its Google acquisition. The flaw isn't the story. The flaw is the infrastructure.
The MeshCentral Mirage
Look closer at the technical details Mandiant chose to release. They mention ShinyHunters deploying a "MeshCentral agent" for persistence and using SSH for lateral movement. MeshCentral is an open-source remote management tool—but it also happens to be the exact same tool used in a 2023 operation by a state-sponsored group that the Five Eyes never formally acknowledged. The timing is too precise. The technique is too rehearsed. ShinyHunters is a convenient label—a boogeyman the press can point to while the real extraction happens under a different flag. Academic institutions were targeted first, Mandiant says. Why academia? Because universities are the honey pots where future elites are trained, where early-stage research on everything from AI to biotech is stored, and where radical ideas can be shaped before they reach the public. The data stolen isn't just payroll numbers—it's behavioral profiles, psychological assessments, donor networks, and unvetted studies that the globalist class wants to bury or weaponize.
The Unanswered Notification
Mandiant claims they notified over 100 organizations, mostly in the United States. But did they notify the public? Did they name the specific universities, hospitals, or government contractors that were compromised? Of course not. Because the real victims are not the IT departments—they are the students, patients, and workers whose data is now sitting on servers controlled by actors who have no accountability. The architecture is clear: a critical flaw that should have been patched years ago is left open, exploited by a group that is either a front or a false flag, and the response is a quiet notification to institutions already captured by the same funding pipelines. Now ask yourself: Who maintains PeopleSoft's source code? Who has the keys to its cryptographic signatures? The same families that sit on the boards of Oracle, Google, and the highest levels of the intelligence community. Follow the charter of the Oracle-Sun Microsystems merger. Follow the 2004 DHS contract that required PeopleSoft to be installed in every state workforce system. The answer is already on page 47 of the public record. You just have to read it.
