Privileged access lives in code where the design put it. ShinyHunters found the back-door allowed by FISA 702 and 47 USC Article 230.
Patching one exploit does not prove that path was removed, and it does not prove a hidden decrypt door was kept. It only proves the vendor closed the hole they admitted with protections under the law.
“No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider.”
~ Article 230
All the exploits do is point to the problem.
So ask yourself... what is the problem?
‼️ BREAKING: Google says ShinyHunters is mass-exploiting an Oracle PeopleSoft flaw, using a trick that slips past the firewall rules companies relied on instead of patching, and has planted web shells on dozens of systems worldwide.
The campaign has spread from universities to healthcare, government, tech and transportation, and some servers got a new backdoor called SIDEEYE, hidden inside a booby-trapped media player installer signed with a valid certificate.
Google has published IOCs, file hashes and a fix-it guide for CVE-2026-35273, and warns victims to prepare for extortion.