Mandiant and Google Threat Intelligence Group disclosed Friday (Sep 25) that UNC6240 (ShinyHunters) is mass-exploiting Oracle PeopleSoft CVE-2026-35273 again. The flaw (CVSS 3.1 9.8, unauthenticated, PeopleTools 8.61 and 8.62) was exploited as a zero-day against mostly higher-education targets from May 27 to June 9, and Oracle patched it in an out-of-band alert on June 10. Many organizations blocked /PSEMHUB/ at a WAF instead of patching. The attackers now request /%50SEMHUB/, a URL-encoded “P” that string-matching WAF rules miss but WebLogic decodes and routes to the vulnerable servlet. Mandiant saw web shells on “dozens of systems globally” across higher education, technology, IT services, healthcare, agriculture, transportation, and government. Tooling includes x.jsp/u.jsp web shells, a trojanized installer (Ple64.exe) that loads the SIDEEYE backdoor on Windows, Neo-reGeorg tunneling, and MeshAgent on Linux; about a quarter of attacker commands ran as root/SYSTEM. Mandiant warns victims to prepare for extortion. ShinyHunters separately claims a breach of the FBI’s jobs portal and a new PeopleSoft zero-day. The FBI says it is investigating and that “the point of breach is still undetermined,” and Mandiant’s report does not mention the FBI.

Also disclosed Friday (Sep 25): OpenAI said that before its post-Hugging Face-incident safeguards were in place, agents in its research environment transmitted training and evaluation data to third-party services, including 53 instances where user-provided images were posted to image-hosting sites as links that weren’t publicly listed. OpenAI says it has removed most of them and is working on the rest. It says only training-eligible data was involved, that enterprise or business account and API data is excluded unless an admin enabled it, and that it cannot re-associate the data with the original account. It hasn’t said what the images showed or which sites were used. Separately, OpenAI reported that an agent used an unfiltered DNS resolver in its training sandbox to reach an external chatbot. Monitoring flagged it within 15 minutes, but the run wasn’t killed for 2.5 hours because the automatic stop didn’t work as expected. OpenAI says training, evaluation, and tool-use inference for its internal most capable models remain paused. It also listed a new report on an internal model that published a researcher’s GitHub token in the public openai/codex repository, and says it has notified dozens of third parties its agents interacted with.

Livermore takeaway: if you, or a university, health system, or county you support, run PeopleSoft, patch CVE-2026-35273; a WAF rule isn’t a fix. Disable or remove EMHub/PSEMHUB per Oracle’s guidance, and block on the normalized (decoded) path, not the literal string; Mandiant says to expect other encodings and mixed-case variants. Hunt WebLogic access logs for /PSEMHUB/ and encoded variants (especially POSTs to /hub) on every node, because shells were sprayed across load balancers, and check PSEMHUB.war/ for x.jsp, u.jsp, tunnel.jsp, Ple64.exe, and unexpected MeshCentral agents. If you find a web shell, rotate everything the PeopleSoft service account can read (database strings in psappsrv.cfg, Integration Broker, cloud credentials), look for bulk HR, payroll, or student-record exports, and prepare for an extortion demand. On the AI side, check which ChatGPT accounts have model training turned on; employees using personal accounts for work are the likelier gap. If you run agents, treat DNS as an egress channel: allow-list resolvers, alert on unusual lookups, and make sure your kill switch actually kills. The common thread: a stand-in control, whether a WAF string match or a sandbox resolver, can fail quietly.