INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ShinyHunters Exploits Oracle PeopleSoft Vulnerability

| 2026-06-11 14:00 LOW HIGH
Executive Summary AI-generated
The threat actors behind the "ShinyHunters" exploit, which targeted the Education sector with Oracle PeopleSoft exploitation, have been quietly expanding their reach. They began by extracting tactical telemetry data from critical infrastructure, including MeshCentral CLI utility commands to execute administrative command queries on compromised remote endpoints. This reconnaissance was followed by general document context and threat detail campaigns, highlighting open attacker directories for public threat reports. The attackers then triaged five sequential IP addresses, staging infrastructure hosting pre-configured Windows MeshCentral agent binaries disguised as Microsoft Azure services. Their agents were hardcoded to establish communication with the command and control server, mimicking legitimate Microsoft Azure NetApp Files endpoints. Global notification response campaigns followed, alerting over 100 exposed organizations to restrict access to vulnerable endpoints. The attackers have been quietly expanding their reach since May 27, 2026, installing MeshCentral remote management servers and automating provisioning of Let's Encrypt SSL certificates for masquerading domains.
Technical Mitigations AI-generated
* Implement secure patching and vulnerability scanning for Oracle PeopleSoft systems to prevent similar exploits. * Configure Linux systems with a strong firewall, intrusion detection system (IDS), and network access control (NAC) to block unauthorized incoming connections. * Regularly update and patch software applications running on the staging servers, including MeshCentral and acme-client, to ensure they have the latest security patches.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign OverviewCampaign OverviewCampaign PriorCampaign Prior
Target & Sectors
Global Scope educationeducation
Incident Timeline
‎May 27, 2026
The threat actors used the MeshCentral remote management server (version 1.1.59) to establish a C2 staging environment on the ShinyHunters public clearnet mirror, which hosts Oracle PeopleSoft configurations and allows them to automate SSL certificate provisioning for azurenetfiles.net.
infrastructure 1.1.59
organisation UTC
observable azurenetfiles.net
organisation SSL
infrastructure Windows
organisation Oracle PeopleSoft
organisation WebLogic
organisation XML
organisation SSH
organisation ShinyHunters
‎May 29, 2026
The attackers used the MeshCentral CLI utility meshctrl.js to execute administrative command queries on compromised remote endpoints.
organisation CLI
‎June 9 2026
Threat actors used an unconfigured Linux meshagent binary to target Higher Education organizations hosting open staging directories on Microsoft Azure NetApp servers.
campaign Campaign Overview
organisation Threat Detail & Campaign Overview On
organisation Higher Education
organisation IP
infrastructure Windows
organisation Microsoft Azure
infrastructure Linux
infrastructure Macos
organisation MeshCentral
organisation Microsoft Azure NetApp
organisation Global Notification Response Campaign Prior
victims 100 exposed organizations
organisation attacker command histories
organisation Technical Analysis & Command History
‎2026/06/11
ShinyHunters exploited vulnerabilities in Oracle PeopleSoft to target the education sector on June 11, 2026.
organisation ShinyHunters Targets Education
organisation Oracle PeopleSoft Exploit
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Macos
Affected Product
Metrics
victims
100
Exposed Organizations
Metrics
infrastructure
‎1.1.59
Software Version