{"id":18392,"date":"2026-08-13T01:05:40","date_gmt":"2026-08-12T18:05:40","guid":{"rendered":"https:\/\/droneth.or.th\/?p=18392"},"modified":"2026-08-13T01:05:40","modified_gmt":"2026-08-12T18:05:40","slug":"oracle-peoplesoft-cve-2026-35273-shinyhunters-zero-day","status":"publish","type":"post","link":"https:\/\/droneth.or.th\/en\/oracle-peoplesoft-cve-2026-35273-shinyhunters-zero-day\/","title":{"rendered":"Oracle PeopleSoft CVE-2026-35273: \u0e27\u0e34\u0e40\u0e04\u0e23\u0e32\u0e30\u0e2b\u0e4c Zero-Day \u0e41\u0e25\u0e30\u0e41\u0e04\u0e21\u0e40\u0e1b\u0e0d ShinyHunters \u0e1b\u0e35 2026"},"content":{"rendered":"<p>\u0e40\u0e14\u0e37\u0e2d\u0e19\u0e21\u0e34\u0e16\u0e38\u0e19\u0e32\u0e22\u0e19 2026 Oracle \u0e2d\u0e2d\u0e01 Security Alert \u0e19\u0e2d\u0e01\u0e01\u0e33\u0e2b\u0e19\u0e14\u0e1b\u0e01\u0e15\u0e34\u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e41\u0e01\u0e49 <strong>CVE-2026-35273<\/strong> \u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48 Remote Code Execution \u0e23\u0e30\u0e14\u0e31\u0e1a Critical \u0e43\u0e19 PeopleSoft PeopleTools \u0e2b\u0e25\u0e31\u0e07 Mandiant \u0e41\u0e25\u0e30 Google Threat Intelligence Group \u0e1e\u0e1a\u0e27\u0e48\u0e32\u0e01\u0e25\u0e38\u0e48\u0e21 UNC6240 \u0e2b\u0e23\u0e37\u0e2d ShinyHunters \u0e43\u0e0a\u0e49\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e19\u0e35\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e08\u0e23\u0e34\u0e07\u0e01\u0e48\u0e2d\u0e19\u0e21\u0e35\u0e41\u0e1e\u0e15\u0e0a\u0e4c<\/p>\n<p>\u0e41\u0e04\u0e21\u0e40\u0e1b\u0e0d\u0e21\u0e38\u0e48\u0e07\u0e40\u0e1b\u0e49\u0e32 PeopleSoft \u0e0b\u0e36\u0e48\u0e07\u0e21\u0e31\u0e01\u0e40\u0e01\u0e47\u0e1a\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25 HR, \u0e01\u0e32\u0e23\u0e40\u0e07\u0e34\u0e19 \u0e41\u0e25\u0e30\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e19\u0e31\u0e01\u0e28\u0e36\u0e01\u0e29\u0e32 \u0e17\u0e33\u0e43\u0e2b\u0e49\u0e20\u0e32\u0e04\u0e2d\u0e38\u0e14\u0e21\u0e28\u0e36\u0e01\u0e29\u0e32\u0e44\u0e14\u0e49\u0e23\u0e31\u0e1a\u0e04\u0e27\u0e32\u0e21\u0e2a\u0e19\u0e43\u0e08\u0e40\u0e1b\u0e47\u0e19\u0e1e\u0e34\u0e40\u0e28\u0e29 \u0e02\u0e48\u0e32\u0e27\u0e2b\u0e25\u0e32\u0e22\u0e41\u0e2b\u0e48\u0e07\u0e2a\u0e23\u0e38\u0e1b\u0e27\u0e48\u0e32 \u201c\u0e21\u0e2b\u0e32\u0e27\u0e34\u0e17\u0e22\u0e32\u0e25\u0e31\u0e22\u0e01\u0e27\u0e48\u0e32 100 \u0e41\u0e2b\u0e48\u0e07\u0e16\u0e39\u0e01\u0e40\u0e08\u0e32\u0e30\u201d \u0e41\u0e15\u0e48\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e15\u0e49\u0e19\u0e17\u0e32\u0e07\u0e23\u0e30\u0e1a\u0e38\u0e27\u0e48\u0e32 Google \u0e41\u0e08\u0e49\u0e07\u0e40\u0e15\u0e37\u0e2d\u0e19\u0e21\u0e32\u0e01\u0e01\u0e27\u0e48\u0e32 100 \u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e17\u0e35\u0e48 IP \u0e2a\u0e31\u0e21\u0e1e\u0e31\u0e19\u0e18\u0e4c\u0e01\u0e31\u0e1a endpoint \u0e0b\u0e36\u0e48\u0e07\u0e2d\u0e32\u0e08\u0e21\u0e35\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48 \u0e42\u0e14\u0e22 68% \u0e02\u0e2d\u0e07\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e17\u0e35\u0e48\u0e44\u0e14\u0e49\u0e23\u0e31\u0e1a\u0e41\u0e08\u0e49\u0e07\u0e2d\u0e22\u0e39\u0e48\u0e43\u0e19\u0e20\u0e32\u0e04\u0e01\u0e32\u0e23\u0e28\u0e36\u0e01\u0e29\u0e32 \u0e44\u0e21\u0e48\u0e43\u0e0a\u0e48\u0e01\u0e32\u0e23\u0e22\u0e37\u0e19\u0e22\u0e31\u0e19\u0e27\u0e48\u0e32\u0e42\u0e14\u0e19\u0e40\u0e08\u0e32\u0e30\u0e04\u0e23\u0e1a\u0e17\u0e31\u0e49\u0e07\u0e2b\u0e21\u0e14<\/p>\n<p>\u0e04\u0e27\u0e32\u0e21\u0e41\u0e15\u0e01\u0e15\u0e48\u0e32\u0e07\u0e19\u0e35\u0e49\u0e2a\u0e33\u0e04\u0e31\u0e0d\u0e17\u0e31\u0e49\u0e07\u0e14\u0e49\u0e32\u0e19 Incident Response \u0e41\u0e25\u0e30\u0e04\u0e27\u0e32\u0e21\u0e19\u0e48\u0e32\u0e40\u0e0a\u0e37\u0e48\u0e2d\u0e16\u0e37\u0e2d\u0e02\u0e2d\u0e07\u0e1a\u0e17\u0e04\u0e27\u0e32\u0e21 Cybersecurity \u0e40\u0e1e\u0e23\u0e32\u0e30\u0e04\u0e33\u0e27\u0e48\u0e32 \u201cpotentially vulnerable\u201d, \u201ctargeted\u201d \u0e41\u0e25\u0e30 \u201cconfirmed compromise\u201d \u0e44\u0e21\u0e48\u0e44\u0e14\u0e49\u0e21\u0e35\u0e04\u0e27\u0e32\u0e21\u0e2b\u0e21\u0e32\u0e22\u0e40\u0e14\u0e35\u0e22\u0e27\u0e01\u0e31\u0e19<\/p>\n<h2>Oracle PeopleSoft \u0e04\u0e37\u0e2d\u0e2d\u0e30\u0e44\u0e23\u0e41\u0e25\u0e30\u0e17\u0e33\u0e44\u0e21\u0e08\u0e36\u0e07\u0e40\u0e1b\u0e47\u0e19\u0e40\u0e1b\u0e49\u0e32\u0e2b\u0e21\u0e32\u0e22\u0e21\u0e39\u0e25\u0e04\u0e48\u0e32\u0e2a\u0e39\u0e07<\/h2>\n<p>Oracle PeopleSoft \u0e40\u0e1b\u0e47\u0e19\u0e0a\u0e38\u0e14 enterprise application \u0e17\u0e35\u0e48\u0e43\u0e0a\u0e49\u0e1a\u0e23\u0e34\u0e2b\u0e32\u0e23\u0e07\u0e32\u0e19 \u0e40\u0e0a\u0e48\u0e19:<\/p>\n<ul>\n<li>Human Capital Management \u0e41\u0e25\u0e30\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e1a\u0e38\u0e04\u0e25\u0e32\u0e01\u0e23<\/li>\n<li>Student administration \u0e41\u0e25\u0e30\u0e17\u0e30\u0e40\u0e1a\u0e35\u0e22\u0e19\u0e19\u0e31\u0e01\u0e28\u0e36\u0e01\u0e29\u0e32<\/li>\n<li>Finance, procurement \u0e41\u0e25\u0e30\u0e1a\u0e31\u0e0d\u0e0a\u0e35<\/li>\n<li>Payroll \u0e41\u0e25\u0e30 benefit<\/li>\n<li>Supply chain \u0e41\u0e25\u0e30\u0e07\u0e32\u0e19\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e2d\u0e37\u0e48\u0e19<\/li>\n<\/ul>\n<p>\u0e23\u0e30\u0e1a\u0e1a\u0e25\u0e31\u0e01\u0e29\u0e13\u0e30\u0e19\u0e35\u0e49\u0e21\u0e31\u0e01\u0e40\u0e0a\u0e37\u0e48\u0e2d\u0e21\u0e01\u0e31\u0e1a directory, database, file share \u0e41\u0e25\u0e30\u0e23\u0e30\u0e1a\u0e1a\u0e20\u0e32\u0e22\u0e43\u0e19\u0e08\u0e33\u0e19\u0e27\u0e19\u0e21\u0e32\u0e01 \u0e21\u0e35\u0e2d\u0e32\u0e22\u0e38\u0e01\u0e32\u0e23\u0e43\u0e0a\u0e49\u0e07\u0e32\u0e19\u0e22\u0e32\u0e27\u0e41\u0e25\u0e30\u0e40\u0e1b\u0e25\u0e35\u0e48\u0e22\u0e19\u0e41\u0e1b\u0e25\u0e07\u0e22\u0e32\u0e01 \u0e2b\u0e32\u0e01 web-facing component \u0e16\u0e39\u0e01\u0e22\u0e36\u0e14 \u0e1c\u0e39\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e2d\u0e32\u0e08\u0e43\u0e0a\u0e49\u0e40\u0e1b\u0e47\u0e19\u0e08\u0e38\u0e14\u0e40\u0e23\u0e34\u0e48\u0e21\u0e15\u0e49\u0e19\u0e44\u0e1b\u0e22\u0e31\u0e07\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e17\u0e35\u0e48\u0e21\u0e35\u0e21\u0e39\u0e25\u0e04\u0e48\u0e32\u0e2a\u0e39\u0e07\u0e41\u0e25\u0e30\u0e23\u0e30\u0e1a\u0e1a\u0e2b\u0e25\u0e31\u0e07\u0e1a\u0e49\u0e32\u0e19<\/p>\n<h2>CVE-2026-35273 \u0e04\u0e37\u0e2d\u0e2d\u0e30\u0e44\u0e23<\/h2>\n<p>Oracle \u0e23\u0e30\u0e1a\u0e38\u0e27\u0e48\u0e32\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e2d\u0e22\u0e39\u0e48\u0e43\u0e19 <strong>Updates Environment Management<\/strong> \u0e02\u0e2d\u0e07 PeopleSoft Enterprise PeopleTools \u0e40\u0e27\u0e2d\u0e23\u0e4c\u0e0a\u0e31\u0e19\u0e17\u0e35\u0e48\u0e44\u0e14\u0e49\u0e23\u0e31\u0e1a\u0e1c\u0e25\u0e01\u0e23\u0e30\u0e17\u0e1a\u0e04\u0e37\u0e2d 8.61 \u0e41\u0e25\u0e30 8.62 \u0e15\u0e32\u0e21 advisory \u0e02\u0e13\u0e30\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22<\/p>\n<p>\u0e04\u0e38\u0e13\u0e25\u0e31\u0e01\u0e29\u0e13\u0e30\u0e17\u0e35\u0e48\u0e17\u0e33\u0e43\u0e2b\u0e49\u0e04\u0e27\u0e32\u0e21\u0e40\u0e2a\u0e35\u0e48\u0e22\u0e07\u0e2a\u0e39\u0e07 \u0e44\u0e14\u0e49\u0e41\u0e01\u0e48:<\/p>\n<ul>\n<li>\u0e42\u0e08\u0e21\u0e15\u0e35\u0e08\u0e32\u0e01\u0e23\u0e30\u0e22\u0e30\u0e44\u0e01\u0e25\u0e1c\u0e48\u0e32\u0e19 HTTP \u0e44\u0e14\u0e49<\/li>\n<li>\u0e44\u0e21\u0e48\u0e15\u0e49\u0e2d\u0e07 authentication<\/li>\n<li>Exploit \u0e2a\u0e33\u0e40\u0e23\u0e47\u0e08\u0e2d\u0e32\u0e08\u0e19\u0e33\u0e44\u0e1b\u0e2a\u0e39\u0e48 Remote Code Execution<\/li>\n<li>\u0e04\u0e30\u0e41\u0e19\u0e19 CVSS 3.1 \u0e40\u0e17\u0e48\u0e32\u0e01\u0e31\u0e1a 9.8<\/li>\n<li>\u0e16\u0e39\u0e01\u0e43\u0e0a\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e01\u0e48\u0e2d\u0e19 Oracle \u0e2d\u0e2d\u0e01\u0e41\u0e1e\u0e15\u0e0a\u0e4c<\/li>\n<li>Target \u0e40\u0e1b\u0e47\u0e19 application infrastructure \u0e17\u0e35\u0e48\u0e40\u0e0a\u0e37\u0e48\u0e2d\u0e21\u0e23\u0e30\u0e1a\u0e1a\u0e2a\u0e33\u0e04\u0e31\u0e0d<\/li>\n<\/ul>\n<p>Mandiant \u0e23\u0e30\u0e1a\u0e38 activity \u0e17\u0e35\u0e48\u0e2a\u0e31\u0e21\u0e1e\u0e31\u0e19\u0e18\u0e4c\u0e01\u0e31\u0e1a Environment Management Hub \u0e2b\u0e23\u0e37\u0e2d <code>PSEMHUB<\/code> endpoint \u0e41\u0e25\u0e30\u0e2d\u0e18\u0e34\u0e1a\u0e32\u0e22 exploit chain \u0e43\u0e19\u0e23\u0e30\u0e14\u0e31\u0e1a\u0e01\u0e32\u0e23\u0e1b\u0e49\u0e2d\u0e07\u0e01\u0e31\u0e19\u0e27\u0e48\u0e32\u0e21\u0e35\u0e40\u0e2a\u0e49\u0e19\u0e17\u0e32\u0e07\u0e08\u0e32\u0e01 SSRF \u0e44\u0e1b\u0e2a\u0e39\u0e48 RCE \u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e04\u0e27\u0e23\u0e43\u0e0a\u0e49 Oracle patch \u0e41\u0e25\u0e30\u0e04\u0e33\u0e41\u0e19\u0e30\u0e19\u0e33\u0e02\u0e2d\u0e07 Mandiant \u0e44\u0e21\u0e48\u0e04\u0e27\u0e23\u0e17\u0e14\u0e2a\u0e2d\u0e1a\u0e14\u0e49\u0e27\u0e22 public exploit \u0e1a\u0e19 production \u0e42\u0e14\u0e22\u0e44\u0e21\u0e48\u0e21\u0e35 authorization<\/p>\n<h2>Timeline \u0e02\u0e2d\u0e07\u0e41\u0e04\u0e21\u0e40\u0e1b\u0e0d<\/h2>\n<div style=\"overflow-x:auto;margin:1.5em 0;\">\n<table style=\"width:100%;border-collapse:collapse;\">\n<thead>\n<tr>\n<th style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e27\u0e31\u0e19\u0e17\u0e35\u0e48<\/th>\n<th style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Incident<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">27 \u0e1e.\u0e04. 2026<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e40\u0e23\u0e34\u0e48\u0e21\u0e0a\u0e48\u0e27\u0e07 activity \u0e17\u0e35\u0e48 Mandiant\/GTIG \u0e15\u0e23\u0e27\u0e08\u0e1e\u0e1a<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e1b\u0e25\u0e32\u0e22 \u0e1e.\u0e04.\u2013\u0e15\u0e49\u0e19 \u0e21\u0e34.\u0e22.<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e21\u0e35\u0e01\u0e32\u0e23\u0e15\u0e31\u0e49\u0e07 staging infrastructure, deploy remote-management agent \u0e41\u0e25\u0e30\u0e2a\u0e33\u0e23\u0e27\u0e08\u0e23\u0e30\u0e1a\u0e1a\u0e20\u0e32\u0e22\u0e43\u0e19<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">9 \u0e21\u0e34.\u0e22. 2026<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e1e\u0e1a\u0e04\u0e27\u0e32\u0e21\u0e2a\u0e31\u0e21\u0e1e\u0e31\u0e19\u0e18\u0e4c\u0e01\u0e31\u0e1a\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e17\u0e35\u0e48\u0e40\u0e1c\u0e22\u0e41\u0e1e\u0e23\u0e48\u0e1a\u0e19 ShinyHunters Data Leak Site<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">10 \u0e21\u0e34.\u0e22. 2026<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Oracle \u0e2d\u0e2d\u0e01 Security Alert \u0e41\u0e25\u0e30 out-of-band patch \u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a CVE-2026-35273<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">11 \u0e21\u0e34.\u0e22. 2026<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Mandiant\/GTIG \u0e40\u0e1c\u0e22\u0e41\u0e1e\u0e23\u0e48\u0e23\u0e32\u0e22\u0e25\u0e30\u0e40\u0e2d\u0e35\u0e22\u0e14 campaign \u0e41\u0e25\u0e30\u0e04\u0e33\u0e41\u0e19\u0e30\u0e19\u0e33\u0e23\u0e31\u0e1a\u0e21\u0e37\u0e2d<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e2b\u0e25\u0e31\u0e07 10 \u0e21\u0e34.\u0e22.<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e2b\u0e19\u0e48\u0e27\u0e22\u0e07\u0e32\u0e19\u0e41\u0e25\u0e30\u0e1c\u0e39\u0e49\u0e02\u0e32\u0e22 security \u0e2d\u0e2d\u0e01 detection\/hardening guidance \u0e40\u0e1e\u0e34\u0e48\u0e21\u0e40\u0e15\u0e34\u0e21<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>\u0e40\u0e1e\u0e23\u0e32\u0e30 activity \u0e40\u0e01\u0e34\u0e14\u0e01\u0e48\u0e2d\u0e19\u0e27\u0e31\u0e19\u0e17\u0e35\u0e48 10 \u0e21\u0e34\u0e16\u0e38\u0e19\u0e32\u0e22\u0e19 \u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e08\u0e36\u0e07\u0e16\u0e39\u0e01\u0e43\u0e0a\u0e49\u0e41\u0e1a\u0e1a Zero-Day \u0e41\u0e21\u0e49\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e08\u0e30\u0e15\u0e34\u0e14 patch \u0e43\u0e19\u0e27\u0e31\u0e19\u0e1b\u0e23\u0e30\u0e01\u0e32\u0e28 \u0e01\u0e47\u0e22\u0e31\u0e07\u0e15\u0e49\u0e2d\u0e07\u0e15\u0e23\u0e27\u0e08\u0e22\u0e49\u0e2d\u0e19\u0e2b\u0e25\u0e31\u0e07\u0e15\u0e31\u0e49\u0e07\u0e41\u0e15\u0e48\u0e01\u0e48\u0e2d\u0e19\u0e27\u0e31\u0e19\u0e17\u0e35\u0e48 27 \u0e1e\u0e24\u0e29\u0e20\u0e32\u0e04\u0e21<\/p>\n<h2>ShinyHunters \u0e2b\u0e23\u0e37\u0e2d UNC6240 \u0e04\u0e37\u0e2d\u0e43\u0e04\u0e23<\/h2>\n<p>ShinyHunters \u0e40\u0e1b\u0e47\u0e19\u0e0a\u0e37\u0e48\u0e2d\u0e17\u0e35\u0e48\u0e43\u0e0a\u0e49\u0e01\u0e31\u0e1a\u0e01\u0e25\u0e38\u0e48\u0e21\u0e2d\u0e32\u0e0a\u0e0d\u0e32\u0e01\u0e23\u0e23\u0e21\u0e44\u0e0b\u0e40\u0e1a\u0e2d\u0e23\u0e4c\u0e17\u0e35\u0e48\u0e40\u0e19\u0e49\u0e19 data theft \u0e41\u0e25\u0e30 extortion \u0e2a\u0e48\u0e27\u0e19 Mandiant \u0e43\u0e0a\u0e49\u0e23\u0e2b\u0e31\u0e2a\u0e15\u0e34\u0e14\u0e15\u0e32\u0e21 <strong>UNC6240<\/strong> \u0e01\u0e32\u0e23\u0e43\u0e0a\u0e49\u0e04\u0e33\u0e27\u0e48\u0e32 \u201cattributed\u201d \u0e43\u0e19\u0e23\u0e32\u0e22\u0e07\u0e32\u0e19 threat intelligence \u0e2b\u0e21\u0e32\u0e22\u0e16\u0e36\u0e07\u0e17\u0e35\u0e21\u0e27\u0e34\u0e40\u0e04\u0e23\u0e32\u0e30\u0e2b\u0e4c\u0e1b\u0e23\u0e30\u0e40\u0e21\u0e34\u0e19\u0e08\u0e32\u0e01 infrastructure, tooling, behavior \u0e41\u0e25\u0e30\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e2d\u0e37\u0e48\u0e19 \u0e44\u0e21\u0e48\u0e44\u0e14\u0e49\u0e40\u0e17\u0e48\u0e32\u0e01\u0e31\u0e1a\u0e04\u0e33\u0e1e\u0e34\u0e1e\u0e32\u0e01\u0e29\u0e32\u0e17\u0e32\u0e07\u0e01\u0e0e\u0e2b\u0e21\u0e32\u0e22<\/p>\n<p>\u0e41\u0e04\u0e21\u0e40\u0e1b\u0e0d\u0e19\u0e35\u0e49\u0e21\u0e35\u0e25\u0e31\u0e01\u0e29\u0e13\u0e30\u0e40\u0e14\u0e48\u0e19\u0e04\u0e37\u0e2d\u0e40\u0e08\u0e32\u0e30\u0e23\u0e30\u0e1a\u0e1a\u0e41\u0e25\u0e49\u0e27\u0e19\u0e33\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e2d\u0e2d\u0e01 \u0e01\u0e48\u0e2d\u0e19\u0e43\u0e0a\u0e49\u0e01\u0e32\u0e23\u0e02\u0e48\u0e21\u0e02\u0e39\u0e48\u0e40\u0e1c\u0e22\u0e41\u0e1e\u0e23\u0e48\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e41\u0e17\u0e19\u0e01\u0e32\u0e23\u0e40\u0e02\u0e49\u0e32\u0e23\u0e2b\u0e31\u0e2a\u0e23\u0e30\u0e1a\u0e1a\u0e40\u0e1e\u0e35\u0e22\u0e07\u0e2d\u0e22\u0e48\u0e32\u0e07\u0e40\u0e14\u0e35\u0e22\u0e27 \u0e23\u0e39\u0e1b\u0e41\u0e1a\u0e1a\u0e14\u0e31\u0e07\u0e01\u0e25\u0e48\u0e32\u0e27\u0e2a\u0e23\u0e49\u0e32\u0e07\u0e41\u0e23\u0e07\u0e01\u0e14\u0e14\u0e31\u0e19\u0e2a\u0e39\u0e07\u0e01\u0e31\u0e1a\u0e21\u0e2b\u0e32\u0e27\u0e34\u0e17\u0e22\u0e32\u0e25\u0e31\u0e22 \u0e40\u0e1e\u0e23\u0e32\u0e30\u0e21\u0e35\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e2a\u0e48\u0e27\u0e19\u0e1a\u0e38\u0e04\u0e04\u0e25\u0e41\u0e25\u0e30\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e01\u0e32\u0e23\u0e28\u0e36\u0e01\u0e29\u0e32\u0e08\u0e33\u0e19\u0e27\u0e19\u0e21\u0e32\u0e01<\/p>\n<h2>Attack Flow \u0e43\u0e19\u0e23\u0e30\u0e14\u0e31\u0e1a\u0e17\u0e35\u0e48\u0e1c\u0e39\u0e49\u0e1b\u0e49\u0e2d\u0e07\u0e01\u0e31\u0e19\u0e04\u0e27\u0e23\u0e23\u0e39\u0e49<\/h2>\n<h3>1. Initial Access \u0e1c\u0e48\u0e32\u0e19 PeopleSoft Endpoint<\/h3>\n<p>\u0e1c\u0e39\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e21\u0e38\u0e48\u0e07\u0e40\u0e1b\u0e49\u0e32 endpoint \u0e02\u0e2d\u0e07 Environment Management \u0e17\u0e35\u0e48\u0e40\u0e1b\u0e34\u0e14\u0e23\u0e31\u0e1a\u0e08\u0e32\u0e01\u0e20\u0e32\u0e22\u0e19\u0e2d\u0e01\u0e41\u0e25\u0e30\u0e43\u0e0a\u0e49 CVE-2026-35273 \u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e23\u0e31\u0e19\u0e04\u0e33\u0e2a\u0e31\u0e48\u0e07\u0e42\u0e14\u0e22\u0e44\u0e21\u0e48\u0e15\u0e49\u0e2d\u0e07\u0e21\u0e35 account<\/p>\n<h3>2. Deploy Remote-Management Agent<\/h3>\n<p>Mandiant \u0e1e\u0e1a customized MeshCentral agent \u0e17\u0e35\u0e48\u0e15\u0e31\u0e49\u0e07\u0e0a\u0e37\u0e48\u0e2d\u0e43\u0e2b\u0e49\u0e14\u0e39\u0e04\u0e25\u0e49\u0e32\u0e22\u0e1a\u0e23\u0e34\u0e01\u0e32\u0e23 cloud \u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e1e\u0e23\u0e32\u0e07\u0e15\u0e31\u0e27 MeshCentral \u0e40\u0e1b\u0e47\u0e19\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07\u0e21\u0e37\u0e2d\u0e1a\u0e23\u0e34\u0e2b\u0e32\u0e23\u0e23\u0e30\u0e1a\u0e1a\u0e17\u0e35\u0e48\u0e16\u0e39\u0e01\u0e15\u0e49\u0e2d\u0e07\u0e15\u0e32\u0e21\u0e01\u0e0e\u0e2b\u0e21\u0e32\u0e22 \u0e41\u0e15\u0e48\u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e16\u0e39\u0e01\u0e14\u0e31\u0e14\u0e41\u0e1b\u0e25\u0e07\u0e2b\u0e23\u0e37\u0e2d\u0e43\u0e0a\u0e49\u0e1c\u0e34\u0e14\u0e27\u0e31\u0e15\u0e16\u0e38\u0e1b\u0e23\u0e30\u0e2a\u0e07\u0e04\u0e4c\u0e44\u0e14\u0e49<\/p>\n<h3>3. Internal Reconnaissance<\/h3>\n<p>\u0e2b\u0e25\u0e31\u0e07\u0e44\u0e14\u0e49 access \u0e1c\u0e39\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e2a\u0e33\u0e23\u0e27\u0e08 PeopleSoft configuration, hostname, IP, mount point \u0e41\u0e25\u0e30 WebLogic configuration \u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e40\u0e02\u0e49\u0e32\u0e43\u0e08 topology \u0e41\u0e25\u0e30\u0e2b\u0e32\u0e40\u0e2a\u0e49\u0e19\u0e17\u0e32\u0e07\u0e44\u0e1b\u0e22\u0e31\u0e07 host \u0e2d\u0e37\u0e48\u0e19<\/p>\n<h3>4. Lateral Movement<\/h3>\n<p>\u0e1e\u0e1a script \u0e17\u0e35\u0e48\u0e1e\u0e22\u0e32\u0e22\u0e32\u0e21\u0e43\u0e0a\u0e49 credential \u0e01\u0e31\u0e1a\u0e23\u0e30\u0e1a\u0e1a\u0e20\u0e32\u0e22\u0e43\u0e19\u0e2b\u0e25\u0e32\u0e22\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07\u0e41\u0e25\u0e30\u0e01\u0e23\u0e30\u0e08\u0e32\u0e22 marker file \u0e44\u0e1b\u0e22\u0e31\u0e07 PeopleSoft component \u0e2d\u0e37\u0e48\u0e19 \u0e1e\u0e24\u0e15\u0e34\u0e01\u0e23\u0e23\u0e21\u0e19\u0e35\u0e49\u0e41\u0e2a\u0e14\u0e07\u0e27\u0e48\u0e32\u0e04\u0e27\u0e32\u0e21\u0e40\u0e2a\u0e35\u0e48\u0e22\u0e07\u0e44\u0e21\u0e48\u0e44\u0e14\u0e49\u0e2b\u0e22\u0e38\u0e14\u0e17\u0e35\u0e48 web tier<\/p>\n<h3>5. Data Staging \u0e41\u0e25\u0e30 Exfiltration<\/h3>\n<p>\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e16\u0e39\u0e01\u0e08\u0e31\u0e14\u0e40\u0e15\u0e23\u0e35\u0e22\u0e21\u0e41\u0e25\u0e30\u0e1a\u0e35\u0e1a\u0e2d\u0e31\u0e14\u0e01\u0e48\u0e2d\u0e19\u0e2a\u0e48\u0e07\u0e2d\u0e2d\u0e01 \u0e21\u0e35\u0e01\u0e32\u0e23\u0e40\u0e0a\u0e37\u0e48\u0e2d\u0e21\u0e15\u0e48\u0e2d\u0e08\u0e32\u0e01 staging infrastructure \u0e44\u0e1b\u0e22\u0e31\u0e07\u0e1b\u0e25\u0e32\u0e22\u0e17\u0e32\u0e07\u0e17\u0e35\u0e48\u0e2a\u0e31\u0e21\u0e1e\u0e31\u0e19\u0e18\u0e4c\u0e01\u0e31\u0e1a data leak site<\/p>\n<h2>\u201c\u0e21\u0e32\u0e01\u0e01\u0e27\u0e48\u0e32 100 \u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u201d \u0e41\u0e25\u0e30 \u201c68%\u201d \u0e15\u0e49\u0e2d\u0e07\u0e15\u0e35\u0e04\u0e27\u0e32\u0e21\u0e2d\u0e22\u0e48\u0e32\u0e07\u0e44\u0e23<\/h2>\n<p>\u0e02\u0e49\u0e2d\u0e04\u0e27\u0e32\u0e21\u0e15\u0e49\u0e19\u0e17\u0e32\u0e07\u0e02\u0e2d\u0e07 Google \u0e23\u0e30\u0e1a\u0e38\u0e27\u0e48\u0e32\u0e44\u0e14\u0e49\u0e41\u0e08\u0e49\u0e07\u0e40\u0e15\u0e37\u0e2d\u0e19\u0e44\u0e1b\u0e22\u0e31\u0e07\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e21\u0e32\u0e01\u0e01\u0e27\u0e48\u0e32 100 \u0e41\u0e2b\u0e48\u0e07\u0e17\u0e31\u0e48\u0e27\u0e42\u0e25\u0e01 \u0e0b\u0e36\u0e48\u0e07 IP address \u0e2a\u0e31\u0e21\u0e1e\u0e31\u0e19\u0e18\u0e4c\u0e01\u0e31\u0e1a potentially vulnerable endpoint \u0e41\u0e25\u0e30 68% \u0e02\u0e2d\u0e07\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e17\u0e35\u0e48\u0e44\u0e14\u0e49\u0e23\u0e31\u0e1a\u0e41\u0e08\u0e49\u0e07\u0e14\u0e33\u0e40\u0e19\u0e34\u0e19\u0e07\u0e32\u0e19\u0e43\u0e19\u0e20\u0e32\u0e04 higher education<\/p>\n<p>\u0e14\u0e31\u0e07\u0e19\u0e31\u0e49\u0e19\u0e04\u0e27\u0e23\u0e41\u0e22\u0e01\u0e2a\u0e16\u0e32\u0e19\u0e30\u0e14\u0e31\u0e07\u0e19\u0e35\u0e49:<\/p>\n<div style=\"overflow-x:auto;margin:1.5em 0;\">\n<table style=\"width:100%;border-collapse:collapse;\">\n<thead>\n<tr>\n<th style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Status<\/th>\n<th style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e04\u0e27\u0e32\u0e21\u0e2b\u0e21\u0e32\u0e22<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Potentially vulnerable<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e1e\u0e1a endpoint\/\u0e40\u0e27\u0e2d\u0e23\u0e4c\u0e0a\u0e31\u0e19\u0e2b\u0e23\u0e37\u0e2d\u0e2a\u0e31\u0e0d\u0e0d\u0e32\u0e13\u0e17\u0e35\u0e48\u0e2d\u0e32\u0e08\u0e40\u0e2a\u0e35\u0e48\u0e22\u0e07 \u0e22\u0e31\u0e07\u0e44\u0e21\u0e48\u0e22\u0e37\u0e19\u0e22\u0e31\u0e19 compromise<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Targeted\/scanned<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e1e\u0e1a\u0e1c\u0e39\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e2a\u0e33\u0e23\u0e27\u0e08\u0e2b\u0e23\u0e37\u0e2d\u0e1e\u0e22\u0e32\u0e22\u0e32\u0e21\u0e40\u0e02\u0e49\u0e32\u0e16\u0e36\u0e07<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Exploited<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e21\u0e35\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19\u0e43\u0e0a\u0e49\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e2a\u0e33\u0e40\u0e23\u0e47\u0e08<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Data exfiltrated<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e22\u0e37\u0e19\u0e22\u0e31\u0e19\u0e27\u0e48\u0e32\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e16\u0e39\u0e01\u0e19\u0e33\u0e2d\u0e2d\u0e01<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Publicly listed<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e0a\u0e37\u0e48\u0e2d\u0e2b\u0e23\u0e37\u0e2d\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e1b\u0e23\u0e32\u0e01\u0e0f\u0e1a\u0e19 leak site<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e01\u0e27\u0e48\u0e32 100 \u0e41\u0e2b\u0e48\u0e07\u0e2d\u0e22\u0e39\u0e48\u0e43\u0e19\u0e01\u0e25\u0e38\u0e48\u0e21\u0e17\u0e35\u0e48\u0e44\u0e14\u0e49\u0e23\u0e31\u0e1a\u0e01\u0e32\u0e23\u0e41\u0e08\u0e49\u0e07\u0e40\u0e15\u0e37\u0e2d\u0e19 \u0e44\u0e21\u0e48\u0e44\u0e14\u0e49\u0e21\u0e35\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19\u0e2a\u0e32\u0e18\u0e32\u0e23\u0e13\u0e30\u0e22\u0e37\u0e19\u0e22\u0e31\u0e19\u0e17\u0e38\u0e01\u0e02\u0e31\u0e49\u0e19\u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a\u0e17\u0e38\u0e01\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23<\/p>\n<h2>\u0e40\u0e2b\u0e15\u0e38\u0e43\u0e14 Higher Education \u0e08\u0e36\u0e07\u0e40\u0e2a\u0e35\u0e48\u0e22\u0e07<\/h2>\n<h3>\u0e21\u0e35\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e2b\u0e25\u0e32\u0e22\u0e1b\u0e23\u0e30\u0e40\u0e20\u0e17\u0e43\u0e19\u0e23\u0e30\u0e1a\u0e1a\u0e40\u0e14\u0e35\u0e22\u0e27<\/h3>\n<p>PeopleSoft \u0e2d\u0e32\u0e08\u0e23\u0e27\u0e21\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e19\u0e31\u0e01\u0e28\u0e36\u0e01\u0e29\u0e32 \u0e1c\u0e39\u0e49\u0e1b\u0e01\u0e04\u0e23\u0e2d\u0e07 \u0e1a\u0e38\u0e04\u0e25\u0e32\u0e01\u0e23 \u0e01\u0e32\u0e23\u0e40\u0e07\u0e34\u0e19 \u0e17\u0e38\u0e19 \u0e41\u0e25\u0e30\u0e40\u0e2d\u0e01\u0e2a\u0e32\u0e23\u0e22\u0e37\u0e19\u0e22\u0e31\u0e19\u0e15\u0e31\u0e27\u0e15\u0e19 \u0e17\u0e33\u0e43\u0e2b\u0e49\u0e01\u0e32\u0e23\u0e40\u0e08\u0e32\u0e30\u0e23\u0e30\u0e1a\u0e1a\u0e2b\u0e19\u0e36\u0e48\u0e07\u0e04\u0e23\u0e31\u0e49\u0e07\u0e21\u0e35\u0e21\u0e39\u0e25\u0e04\u0e48\u0e32\u0e2a\u0e39\u0e07<\/p>\n<h3>Environment \u0e0b\u0e31\u0e1a\u0e0b\u0e49\u0e2d\u0e19\u0e41\u0e25\u0e30\u0e21\u0e35 Legacy Dependency<\/h3>\n<p>\u0e23\u0e30\u0e1a\u0e1a enterprise \u0e17\u0e35\u0e48\u0e43\u0e0a\u0e49\u0e21\u0e32\u0e19\u0e32\u0e19\u0e2d\u0e32\u0e08\u0e21\u0e35 customization, integration \u0e41\u0e25\u0e30 downtime constraint \u0e17\u0e33\u0e43\u0e2b\u0e49 patch \u0e44\u0e21\u0e48\u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e25\u0e07\u0e17\u0e31\u0e19\u0e17\u0e35\u0e42\u0e14\u0e22\u0e44\u0e21\u0e48\u0e17\u0e14\u0e2a\u0e2d\u0e1a<\/p>\n<h3>User Population \u0e43\u0e2b\u0e0d\u0e48\u0e41\u0e25\u0e30\u0e40\u0e1b\u0e25\u0e35\u0e48\u0e22\u0e19\u0e15\u0e25\u0e2d\u0e14<\/h3>\n<p>\u0e19\u0e31\u0e01\u0e28\u0e36\u0e01\u0e29\u0e32 \u0e2d\u0e32\u0e08\u0e32\u0e23\u0e22\u0e4c \u0e1e\u0e19\u0e31\u0e01\u0e07\u0e32\u0e19 \u0e1c\u0e39\u0e49\u0e23\u0e31\u0e1a\u0e40\u0e2b\u0e21\u0e32 \u0e41\u0e25\u0e30\u0e28\u0e34\u0e29\u0e22\u0e4c\u0e40\u0e01\u0e48\u0e32\u0e21\u0e35 lifecycle \u0e15\u0e48\u0e32\u0e07\u0e01\u0e31\u0e19 Identity sprawl \u0e41\u0e25\u0e30 account \u0e40\u0e01\u0e48\u0e32\u0e08\u0e36\u0e07\u0e40\u0e1b\u0e47\u0e19\u0e1b\u0e31\u0e0d\u0e2b\u0e32<\/p>\n<h3>\u0e07\u0e1a Security \u0e44\u0e21\u0e48\u0e2a\u0e21\u0e14\u0e38\u0e25\u0e01\u0e31\u0e1a Attack Surface<\/h3>\n<p>\u0e21\u0e2b\u0e32\u0e27\u0e34\u0e17\u0e22\u0e32\u0e25\u0e31\u0e22\u0e21\u0e35 network \u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e2a\u0e19\u0e31\u0e1a\u0e2a\u0e19\u0e38\u0e19\u0e01\u0e32\u0e23\u0e40\u0e23\u0e35\u0e22\u0e19\u0e41\u0e25\u0e30\u0e27\u0e34\u0e08\u0e31\u0e22 \u0e41\u0e15\u0e48\u0e17\u0e35\u0e21 security \u0e2d\u0e32\u0e08\u0e40\u0e25\u0e47\u0e01\u0e01\u0e27\u0e48\u0e32\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e40\u0e2d\u0e01\u0e0a\u0e19\u0e17\u0e35\u0e48\u0e21\u0e35\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e02\u0e19\u0e32\u0e14\u0e43\u0e01\u0e25\u0e49\u0e01\u0e31\u0e19<\/p>\n<h2>\u0e27\u0e34\u0e18\u0e35\u0e15\u0e23\u0e27\u0e08\u0e2a\u0e2d\u0e1a Exposure<\/h2>\n<ol>\n<li>\u0e17\u0e33 inventory \u0e27\u0e48\u0e32\u0e21\u0e35 PeopleSoft PeopleTools 8.61\/8.62 \u0e41\u0e25\u0e30 Environment Management component \u0e17\u0e35\u0e48\u0e43\u0e14<\/li>\n<li>\u0e15\u0e23\u0e27\u0e08\u0e27\u0e48\u0e32 <code>PSEMHUB<\/code> \u0e2b\u0e23\u0e37\u0e2d administrative endpoint \u0e40\u0e02\u0e49\u0e32\u0e16\u0e36\u0e07\u0e08\u0e32\u0e01 internet \u0e2b\u0e23\u0e37\u0e2d untrusted network \u0e44\u0e14\u0e49\u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/li>\n<li>\u0e15\u0e23\u0e27\u0e08\u0e2a\u0e16\u0e32\u0e19\u0e30 Oracle Security Alert \u0e41\u0e25\u0e30 Critical Patch Update \u0e25\u0e48\u0e32\u0e2a\u0e38\u0e14<\/li>\n<li>\u0e23\u0e30\u0e1a\u0e38\u0e17\u0e38\u0e01 node \u0e02\u0e2d\u0e07 PeopleSoft \u0e44\u0e21\u0e48\u0e15\u0e23\u0e27\u0e08\u0e40\u0e09\u0e1e\u0e32\u0e30 load balancer<\/li>\n<li>\u0e15\u0e23\u0e27\u0e08 integration \u0e01\u0e31\u0e1a WebLogic, database, NFS\/file share, directory \u0e41\u0e25\u0e30 backup<\/li>\n<\/ol>\n<p>\u0e2b\u0e32\u0e01 asset inventory \u0e44\u0e21\u0e48\u0e04\u0e23\u0e1a \u0e04\u0e27\u0e23\u0e43\u0e0a\u0e49\u0e17\u0e31\u0e49\u0e07 CMDB, network discovery, DNS, load-balancer configuration \u0e41\u0e25\u0e30 cloud inventory \u0e1b\u0e23\u0e30\u0e01\u0e2d\u0e1a\u0e01\u0e31\u0e19<\/p>\n<h2>Detection \u0e41\u0e25\u0e30 Threat Hunting<\/h2>\n<p>Mandiant \u0e41\u0e19\u0e30\u0e19\u0e33\u0e43\u0e2b\u0e49\u0e15\u0e23\u0e27\u0e08\u0e2b\u0e25\u0e32\u0e22\u0e23\u0e30\u0e14\u0e31\u0e1a:<\/p>\n<h3>Web\/Application Log<\/h3>\n<ul>\n<li>HTTP POST \u0e44\u0e1b\u0e22\u0e31\u0e07 administrative endpoint \u0e08\u0e32\u0e01 external source<\/li>\n<li>Request \u0e17\u0e35\u0e48\u0e21\u0e35 loopback\/internal address \u0e43\u0e19\u0e1a\u0e23\u0e34\u0e1a\u0e17\u0e17\u0e35\u0e48\u0e44\u0e21\u0e48\u0e04\u0e27\u0e23\u0e21\u0e35<\/li>\n<li>User agent, path \u0e41\u0e25\u0e30 response pattern \u0e1c\u0e34\u0e14\u0e1b\u0e01\u0e15\u0e34<\/li>\n<li>Access \u0e43\u0e19\u0e0a\u0e48\u0e27\u0e07\u0e40\u0e27\u0e25\u0e32\u0e17\u0e35\u0e48\u0e44\u0e21\u0e48\u0e21\u0e35\u0e07\u0e32\u0e19\u0e14\u0e39\u0e41\u0e25\u0e23\u0e30\u0e1a\u0e1a<\/li>\n<\/ul>\n<h3>Host\/File System<\/h3>\n<ul>\n<li>JSP \u0e2b\u0e23\u0e37\u0e2d executable \u0e17\u0e35\u0e48\u0e44\u0e21\u0e48\u0e2d\u0e22\u0e39\u0e48\u0e43\u0e19 baseline<\/li>\n<li>\u0e44\u0e1f\u0e25\u0e4c\/\u0e42\u0e1f\u0e25\u0e40\u0e14\u0e2d\u0e23\u0e4c\u0e43\u0e2b\u0e21\u0e48\u0e43\u0e15\u0e49 PSEMHUB \u0e41\u0e25\u0e30 WebLogic application<\/li>\n<li>Remote-management agent \u0e17\u0e35\u0e48\u0e0a\u0e37\u0e48\u0e2d\u0e04\u0e25\u0e49\u0e32\u0e22 cloud service<\/li>\n<li>Marker file \u0e2b\u0e23\u0e37\u0e2d script \u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a lateral movement<\/li>\n<li><code>.bash_history<\/code> \u0e2b\u0e23\u0e37\u0e2d process history \u0e17\u0e35\u0e48\u0e41\u0e2a\u0e14\u0e07 reconnaissance<\/li>\n<\/ul>\n<h3>Network<\/h3>\n<ul>\n<li>Outbound connection \u0e08\u0e32\u0e01 PeopleSoft web tier \u0e44\u0e1b internet<\/li>\n<li>SMB\/SSH traffic \u0e08\u0e32\u0e01 application server \u0e44\u0e1b\u0e1b\u0e25\u0e32\u0e22\u0e17\u0e32\u0e07\u0e17\u0e35\u0e48\u0e44\u0e21\u0e48\u0e40\u0e04\u0e22\u0e15\u0e34\u0e14\u0e15\u0e48\u0e2d<\/li>\n<li>C2 domain\/IP \u0e08\u0e32\u0e01 threat intelligence \u0e25\u0e48\u0e32\u0e2a\u0e38\u0e14<\/li>\n<li>Data transfer \u0e1b\u0e23\u0e34\u0e21\u0e32\u0e13\u0e1c\u0e34\u0e14\u0e1b\u0e01\u0e15\u0e34\u0e2b\u0e23\u0e37\u0e2d archive \u0e02\u0e19\u0e32\u0e14\u0e43\u0e2b\u0e0d\u0e48<\/li>\n<\/ul>\n<p>IoC \u0e40\u0e1b\u0e25\u0e35\u0e48\u0e22\u0e19\u0e44\u0e14\u0e49\u0e41\u0e25\u0e30 attacker \u0e2d\u0e32\u0e08\u0e22\u0e49\u0e32\u0e22 infrastructure \u0e01\u0e32\u0e23 hunt \u0e08\u0e36\u0e07\u0e15\u0e49\u0e2d\u0e07\u0e14\u0e39 behavior \u0e23\u0e48\u0e27\u0e21\u0e01\u0e31\u0e1a indicator<\/p>\n<h2>\u0e41\u0e19\u0e27\u0e17\u0e32\u0e07 Remediation<\/h2>\n<h3>1. Patch \u0e17\u0e31\u0e19\u0e17\u0e35<\/h3>\n<p>\u0e17\u0e33\u0e15\u0e32\u0e21 <a href=\"https:\/\/www.oracle.com\/security-alerts\/alert-cve-2026-35273.html\" target=\"_blank\" rel=\"noopener\">Oracle Security Alert CVE-2026-35273<\/a> \u0e41\u0e25\u0e30\u0e15\u0e34\u0e14 Critical Patch Update \u0e25\u0e48\u0e32\u0e2a\u0e38\u0e14\u0e01\u0e31\u0e1a\u0e17\u0e38\u0e01 environment<\/p>\n<h3>2. \u0e1b\u0e34\u0e14\u0e2b\u0e23\u0e37\u0e2d\u0e41\u0e22\u0e01 Environment Management Hub<\/h3>\n<p>\u0e2b\u0e32\u0e01\u0e44\u0e21\u0e48\u0e08\u0e33\u0e40\u0e1b\u0e47\u0e19\u0e43\u0e2b\u0e49 disable\/remove \u0e15\u0e32\u0e21 guidance \u0e2b\u0e32\u0e01\u0e08\u0e33\u0e40\u0e1b\u0e47\u0e19\u0e15\u0e49\u0e2d\u0e07\u0e43\u0e0a\u0e49 \u0e43\u0e2b\u0e49\u0e08\u0e33\u0e01\u0e31\u0e14\u0e40\u0e09\u0e1e\u0e32\u0e30 management network \u0e41\u0e25\u0e30 block external access \u0e17\u0e35\u0e48 perimeter<\/p>\n<h3>3. Preserve Evidence \u0e01\u0e48\u0e2d\u0e19 Cleanup<\/h3>\n<p>\u0e40\u0e01\u0e47\u0e1a log, snapshot, volatile data \u0e41\u0e25\u0e30 artifact \u0e01\u0e48\u0e2d\u0e19\u0e25\u0e1a\u0e44\u0e1f\u0e25\u0e4c \u0e2b\u0e32\u0e01\u0e23\u0e35\u0e1a\u0e25\u0e49\u0e32\u0e07\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07\u0e42\u0e14\u0e22\u0e44\u0e21\u0e48\u0e40\u0e01\u0e47\u0e1a\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19 \u0e2d\u0e32\u0e08\u0e44\u0e21\u0e48\u0e17\u0e23\u0e32\u0e1a\u0e27\u0e48\u0e32 attacker \u0e44\u0e1b\u0e16\u0e36\u0e07\u0e23\u0e30\u0e1a\u0e1a\u0e43\u0e14\u0e1a\u0e49\u0e32\u0e07<\/p>\n<h3>4. Scope Credential Compromise<\/h3>\n<p>\u0e15\u0e23\u0e27\u0e08 secret \u0e43\u0e19 configuration, service account, SSH key, database credential \u0e41\u0e25\u0e30 credential \u0e17\u0e35\u0e48 agent\/process \u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e2d\u0e48\u0e32\u0e19\u0e44\u0e14\u0e49 \u0e2b\u0e21\u0e38\u0e19 credential \u0e2b\u0e25\u0e31\u0e07 containment<\/p>\n<h3>5. Rebuild \u0e40\u0e21\u0e37\u0e48\u0e2d\u0e1e\u0e1a RCE\/Persistence<\/h3>\n<p>\u0e2b\u0e32\u0e01\u0e22\u0e37\u0e19\u0e22\u0e31\u0e19 RCE \u0e41\u0e25\u0e30 remote agent \u0e01\u0e32\u0e23 rebuild \u0e08\u0e32\u0e01 trusted baseline \u0e1e\u0e23\u0e49\u0e2d\u0e21 restore \u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e17\u0e35\u0e48\u0e15\u0e23\u0e27\u0e08\u0e41\u0e25\u0e49\u0e27\u0e21\u0e31\u0e01\u0e1b\u0e25\u0e2d\u0e14\u0e20\u0e31\u0e22\u0e01\u0e27\u0e48\u0e32\u0e01\u0e32\u0e23\u0e25\u0e1a artifact \u0e40\u0e1b\u0e47\u0e19\u0e23\u0e32\u0e22\u0e44\u0e1f\u0e25\u0e4c<\/p>\n<h2>Hardening \u0e23\u0e30\u0e22\u0e30\u0e22\u0e32\u0e27<\/h2>\n<ul>\n<li>\u0e44\u0e21\u0e48\u0e40\u0e1b\u0e34\u0e14 administrative component \u0e2a\u0e39\u0e48 internet<\/li>\n<li>\u0e43\u0e0a\u0e49 network segmentation \u0e23\u0e30\u0e2b\u0e27\u0e48\u0e32\u0e07 web, app, database \u0e41\u0e25\u0e30 management<\/li>\n<li>\u0e08\u0e33\u0e01\u0e31\u0e14 outbound network \u0e02\u0e2d\u0e07 PeopleSoft host<\/li>\n<li>\u0e43\u0e0a\u0e49 service account \u0e41\u0e22\u0e01\u0e41\u0e25\u0e30 least privilege<\/li>\n<li>\u0e40\u0e01\u0e47\u0e1a log \u0e44\u0e1b\u0e22\u0e31\u0e07 SIEM \u0e19\u0e2d\u0e01\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07<\/li>\n<li>\u0e17\u0e33 file-integrity monitoring \u0e01\u0e31\u0e1a WebLogic\/PeopleSoft directory<\/li>\n<li>\u0e17\u0e14\u0e2a\u0e2d\u0e1a patch \u0e43\u0e19 pre-production \u0e43\u0e2b\u0e49\u0e1e\u0e23\u0e49\u0e2d\u0e21 deploy \u0e41\u0e1a\u0e1a\u0e40\u0e23\u0e48\u0e07\u0e14\u0e48\u0e27\u0e19<\/li>\n<li>\u0e17\u0e33 tabletop exercise \u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a Zero-Day \u0e17\u0e35\u0e48 vendor \u0e22\u0e31\u0e07\u0e44\u0e21\u0e48\u0e21\u0e35 patch<\/li>\n<li>\u0e17\u0e1a\u0e17\u0e27\u0e19 EOL version \u0e41\u0e25\u0e30 customization \u0e17\u0e35\u0e48\u0e02\u0e27\u0e32\u0e07\u0e01\u0e32\u0e23\u0e2d\u0e31\u0e1b\u0e40\u0e01\u0e23\u0e14<\/li>\n<\/ul>\n<h2>\u0e1a\u0e17\u0e40\u0e23\u0e35\u0e22\u0e19\u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a Penetration Testing<\/h2>\n<p>Pentest PeopleSoft \u0e44\u0e21\u0e48\u0e04\u0e27\u0e23\u0e15\u0e23\u0e27\u0e08\u0e40\u0e09\u0e1e\u0e32\u0e30 login page \u0e15\u0e49\u0e2d\u0e07\u0e04\u0e23\u0e2d\u0e1a\u0e04\u0e25\u0e38\u0e21:<\/p>\n<ul>\n<li>Administrative endpoint exposure<\/li>\n<li>Trust \u0e23\u0e30\u0e2b\u0e27\u0e48\u0e32\u0e07 PeopleSoft component<\/li>\n<li>Service account \u0e41\u0e25\u0e30 secret storage<\/li>\n<li>SSRF \u0e41\u0e25\u0e30 internal access control<\/li>\n<li>Segmentation \u0e23\u0e30\u0e2b\u0e27\u0e48\u0e32\u0e07 web\/app\/database<\/li>\n<li>Business role \u0e41\u0e25\u0e30 authorization<\/li>\n<li>Detection \u0e02\u0e2d\u0e07 command execution \u0e41\u0e25\u0e30 remote-management tool<\/li>\n<\/ul>\n<p>\u0e01\u0e32\u0e23\u0e17\u0e14\u0e2a\u0e2d\u0e1a production \u0e15\u0e49\u0e2d\u0e07\u0e43\u0e0a\u0e49 safe payload \u0e41\u0e25\u0e30 test account \u0e40\u0e1e\u0e23\u0e32\u0e30 PeopleSoft \u0e23\u0e2d\u0e07\u0e23\u0e31\u0e1a\u0e07\u0e32\u0e19\u0e18\u0e38\u0e23\u0e01\u0e34\u0e08\u0e2a\u0e33\u0e04\u0e31\u0e0d \u0e01\u0e32\u0e23\u0e17\u0e33\u0e43\u0e2b\u0e49 process scheduler \u0e2b\u0e23\u0e37\u0e2d integration \u0e25\u0e48\u0e21\u0e2d\u0e32\u0e08\u0e01\u0e23\u0e30\u0e17\u0e1a payroll \u0e41\u0e25\u0e30\u0e07\u0e32\u0e19\u0e17\u0e30\u0e40\u0e1a\u0e35\u0e22\u0e19<\/p>\n<h2>FAQ<\/h2>\n<h3>\u0e21\u0e35\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e16\u0e39\u0e01\u0e40\u0e08\u0e32\u0e30\u0e21\u0e32\u0e01\u0e01\u0e27\u0e48\u0e32 100 \u0e41\u0e2b\u0e48\u0e07\u0e08\u0e23\u0e34\u0e07\u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/h3>\n<p>\u0e41\u0e2b\u0e25\u0e48\u0e07 Google \u0e23\u0e30\u0e1a\u0e38\u0e27\u0e48\u0e32\u0e41\u0e08\u0e49\u0e07\u0e40\u0e15\u0e37\u0e2d\u0e19\u0e21\u0e32\u0e01\u0e01\u0e27\u0e48\u0e32 100 \u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e17\u0e35\u0e48 IP \u0e2a\u0e31\u0e21\u0e1e\u0e31\u0e19\u0e18\u0e4c\u0e01\u0e31\u0e1a potentially vulnerable endpoint \u0e44\u0e21\u0e48\u0e43\u0e0a\u0e48\u0e22\u0e37\u0e19\u0e22\u0e31\u0e19\u0e27\u0e48\u0e32 compromise \u0e04\u0e23\u0e1a\u0e17\u0e38\u0e01\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23<\/p>\n<h3>68% \u0e2b\u0e21\u0e32\u0e22\u0e16\u0e36\u0e07\u0e40\u0e2b\u0e22\u0e37\u0e48\u0e2d\u0e40\u0e1b\u0e47\u0e19\u0e21\u0e2b\u0e32\u0e27\u0e34\u0e17\u0e22\u0e32\u0e25\u0e31\u0e22 68% \u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/h3>\n<p>\u0e2b\u0e21\u0e32\u0e22\u0e16\u0e36\u0e07 68% \u0e02\u0e2d\u0e07\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e17\u0e35\u0e48 Google \u0e41\u0e08\u0e49\u0e07\u0e40\u0e15\u0e37\u0e2d\u0e19\u0e2d\u0e22\u0e39\u0e48\u0e43\u0e19 higher education \u0e44\u0e21\u0e48\u0e43\u0e0a\u0e48\u0e2a\u0e16\u0e34\u0e15\u0e34\u0e2a\u0e38\u0e14\u0e17\u0e49\u0e32\u0e22\u0e02\u0e2d\u0e07\u0e40\u0e2b\u0e22\u0e37\u0e48\u0e2d\u0e22\u0e37\u0e19\u0e22\u0e31\u0e19\u0e17\u0e31\u0e48\u0e27\u0e42\u0e25\u0e01<\/p>\n<h3>\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e15\u0e49\u0e2d\u0e07\u0e21\u0e35 Account \u0e01\u0e48\u0e2d\u0e19\u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/h3>\n<p>Oracle \u0e23\u0e30\u0e1a\u0e38\u0e27\u0e48\u0e32 remotely exploitable without authentication<\/p>\n<h3>\u0e41\u0e04\u0e48\u0e15\u0e34\u0e14 Patch \u0e40\u0e1e\u0e35\u0e22\u0e07\u0e1e\u0e2d\u0e44\u0e2b\u0e21<\/h3>\n<p>\u0e44\u0e21\u0e48 \u0e2b\u0e32\u0e01\u0e23\u0e30\u0e1a\u0e1a\u0e40\u0e1b\u0e34\u0e14\u0e23\u0e31\u0e1a internet \u0e01\u0e48\u0e2d\u0e19\u0e41\u0e1e\u0e15\u0e0a\u0e4c \u0e15\u0e49\u0e2d\u0e07\u0e15\u0e23\u0e27\u0e08\u0e22\u0e49\u0e2d\u0e19\u0e2b\u0e25\u0e31\u0e07\u0e41\u0e25\u0e30 hunt persistence \u0e40\u0e1e\u0e23\u0e32\u0e30 patch \u0e44\u0e21\u0e48\u0e25\u0e1a backdoor \u0e2b\u0e23\u0e37\u0e2d credential \u0e17\u0e35\u0e48\u0e16\u0e39\u0e01\u0e02\u0e42\u0e21\u0e22\u0e44\u0e1b\u0e41\u0e25\u0e49\u0e27<\/p>\n<h3>WAF \u0e1b\u0e49\u0e2d\u0e07\u0e01\u0e31\u0e19\u0e44\u0e14\u0e49\u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/h3>\n<p>WAF \u0e2d\u0e32\u0e08\u0e0a\u0e48\u0e27\u0e22\u0e40\u0e1b\u0e47\u0e19 compensating control \u0e1a\u0e32\u0e07\u0e2a\u0e48\u0e27\u0e19 \u0e41\u0e15\u0e48\u0e44\u0e21\u0e48\u0e04\u0e27\u0e23\u0e43\u0e0a\u0e49\u0e41\u0e17\u0e19 patch \u0e41\u0e25\u0e30 network restriction Mandiant \u0e40\u0e15\u0e37\u0e2d\u0e19\u0e27\u0e48\u0e32\u0e01\u0e32\u0e23\u0e1e\u0e36\u0e48\u0e07 body-inspection rule \u0e40\u0e1e\u0e35\u0e22\u0e07\u0e2d\u0e22\u0e48\u0e32\u0e07\u0e40\u0e14\u0e35\u0e22\u0e27\u0e2d\u0e32\u0e08\u0e16\u0e39\u0e01 bypass<\/p>\n<h2>Summary<\/h2>\n<p>CVE-2026-35273 \u0e41\u0e2a\u0e14\u0e07\u0e43\u0e2b\u0e49\u0e40\u0e2b\u0e47\u0e19\u0e27\u0e48\u0e32\u0e23\u0e30\u0e1a\u0e1a enterprise \u0e17\u0e35\u0e48\u0e14\u0e39\u0e40\u0e2b\u0e21\u0e37\u0e2d\u0e19\u0e40\u0e1b\u0e47\u0e19 back-office \u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e40\u0e1b\u0e47\u0e19 internet-facing attack surface \u0e17\u0e35\u0e48\u0e21\u0e35 blast radius \u0e2a\u0e39\u0e07\u0e21\u0e32\u0e01 \u0e40\u0e21\u0e37\u0e48\u0e2d Zero-Day \u0e40\u0e1b\u0e34\u0e14\u0e17\u0e32\u0e07\u0e2a\u0e39\u0e48 RCE \u0e1c\u0e39\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e40\u0e1b\u0e25\u0e35\u0e48\u0e22\u0e19 application server \u0e40\u0e1b\u0e47\u0e19\u0e08\u0e38\u0e14\u0e2a\u0e33\u0e23\u0e27\u0e08\u0e41\u0e25\u0e30\u0e40\u0e04\u0e25\u0e37\u0e48\u0e2d\u0e19\u0e17\u0e35\u0e48\u0e43\u0e19\u0e40\u0e04\u0e23\u0e37\u0e2d\u0e02\u0e48\u0e32\u0e22<\/p>\n<p>\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e04\u0e27\u0e23\u0e17\u0e33\u0e21\u0e32\u0e01\u0e01\u0e27\u0e48\u0e32\u0e01\u0e32\u0e23\u0e15\u0e34\u0e14 patch \u0e44\u0e14\u0e49\u0e41\u0e01\u0e48\u0e1b\u0e34\u0e14 administrative endpoint \u0e08\u0e32\u0e01\u0e20\u0e32\u0e22\u0e19\u0e2d\u0e01 \u0e15\u0e23\u0e27\u0e08\u0e22\u0e49\u0e2d\u0e19\u0e2b\u0e25\u0e31\u0e07\u0e15\u0e31\u0e49\u0e07\u0e41\u0e15\u0e48\u0e01\u0e48\u0e2d\u0e19\u0e27\u0e31\u0e19\u0e17\u0e35\u0e48 27 \u0e1e\u0e24\u0e29\u0e20\u0e32\u0e04\u0e21 \u0e40\u0e01\u0e47\u0e1a\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19 forensic \u0e2b\u0e21\u0e38\u0e19 credential \u0e41\u0e25\u0e30\u0e17\u0e1a\u0e17\u0e27\u0e19 segmentation \u0e2a\u0e48\u0e27\u0e19\u0e1c\u0e39\u0e49\u0e40\u0e02\u0e35\u0e22\u0e19\u0e02\u0e48\u0e32\u0e27\u0e04\u0e27\u0e23\u0e23\u0e30\u0e1a\u0e38\u0e43\u0e2b\u0e49\u0e0a\u0e31\u0e14\u0e27\u0e48\u0e32\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e01\u0e27\u0e48\u0e32 100 \u0e41\u0e2b\u0e48\u0e07\u0e40\u0e1b\u0e47\u0e19\u0e01\u0e25\u0e38\u0e48\u0e21\u0e17\u0e35\u0e48\u0e44\u0e14\u0e49\u0e23\u0e31\u0e1a\u0e01\u0e32\u0e23\u0e41\u0e08\u0e49\u0e07\u0e40\u0e15\u0e37\u0e2d\u0e19\u0e27\u0e48\u0e32\u0e2d\u0e32\u0e08\u0e40\u0e2a\u0e35\u0e48\u0e22\u0e07 \u0e44\u0e21\u0e48\u0e43\u0e0a\u0e48\u0e08\u0e33\u0e19\u0e27\u0e19\u0e40\u0e2b\u0e22\u0e37\u0e48\u0e2d\u0e22\u0e37\u0e19\u0e22\u0e31\u0e19\u0e17\u0e31\u0e49\u0e07\u0e2b\u0e21\u0e14<\/p>\n<h2>\u0e2d\u0e48\u0e32\u0e19\u0e15\u0e48\u0e2d<\/h2>\n<ul>\n<li><a href=\"\/en\/04-cpanel-cve-2026-41940-zero-day.md\/\">cPanel CVE-2026-41940<\/a><\/li>\n<li><a href=\"\/en\/06-check-point-vpn-cve-2026-50751-qilin.md\/\">Check Point VPN CVE-2026-50751<\/a><\/li>\n<li><a href=\"\/en\/11-unc3886-singapore-telcos-zero-day.md\/\">UNC3886 \u0e42\u0e08\u0e21\u0e15\u0e35 4 \u0e04\u0e48\u0e32\u0e22\u0e21\u0e37\u0e2d\u0e16\u0e37\u0e2d\u0e2a\u0e34\u0e07\u0e04\u0e42\u0e1b\u0e23\u0e4c<\/a><\/li>\n<\/ul>\n<h2>\u0e41\u0e2b\u0e25\u0e48\u0e07\u0e2d\u0e49\u0e32\u0e07\u0e2d\u0e34\u0e07<\/h2>\n<ol>\n<li><a href=\"https:\/\/www.oracle.com\/security-alerts\/alert-cve-2026-35273.html\" target=\"_blank\" rel=\"noopener\">Oracle Security Alert \u2014 CVE-2026-35273<\/a><\/li>\n<li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cve-2026-35273verbose.html\" target=\"_blank\" rel=\"noopener\">Oracle \u2014 CVE-2026-35273 Risk Matrix<\/a><\/li>\n<li><a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/shinyhunters-targets-education-sector-oracle-exploit\" target=\"_blank\" rel=\"noopener\">Google Cloud\/Mandiant \u2014 ShinyHunters Targets Education Sector<\/a><\/li>\n<li><a href=\"https:\/\/www.rapid7.com\/blog\/post\/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273\/\" target=\"_blank\" rel=\"noopener\">Rapid7 \u2014 Active Exploitation of Oracle PeopleSoft Zero-Day<\/a><\/li>\n<li><a href=\"https:\/\/www.helpnetsecurity.com\/2026\/06\/11\/oracle-peoplesoft-under-attack-cve-2026-35273\/\" target=\"_blank\" rel=\"noopener\">Help Net Security \u2014 Oracle PeopleSoft servers under attack<\/a><\/li>\n<\/ol>","protected":false},"excerpt":{"rendered":"<p>\u0e40\u0e08\u0e32\u0e30\u0e25\u0e36\u0e01 Oracle PeopleSoft Zero-Day CVE-2026-35273 \u0e17\u0e35\u0e48 ShinyHunters \u0e43\u0e0a\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e20\u0e32\u0e04\u0e01\u0e32\u0e23\u0e28\u0e36\u0e01\u0e29\u0e32 \u0e1e\u0e23\u0e49\u0e2d\u0e21\u0e41\u0e01\u0e49\u0e04\u0e27\u0e32\u0e21\u0e40\u0e02\u0e49\u0e32\u0e43\u0e08\u0e40\u0e23\u0e37\u0e48\u0e2d\u0e07 100 \u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23, 68%, \u0e27\u0e34\u0e18\u0e35\u0e15\u0e23\u0e27\u0e08\u0e2a\u0e2d\u0e1a\u0e41\u0e25\u0e30\u0e41\u0e19\u0e27\u0e17\u0e32\u0e07\u0e1b\u0e49\u0e2d\u0e07\u0e01\u0e31\u0e19<\/p>","protected":false},"author":0,"featured_media":18424,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[264,265],"tags":[294,297,293,298,295,296,289],"class_list":["post-18392","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-zero-day-vulnerability","tag-cve-2026-35273","tag-higher-education","tag-oracle-peoplesoft","tag-rce","tag-shinyhunters","tag-unc6240","tag-zero-day"],"acf":[],"rttpg_featured_image_url":{"full":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/05.jpg",1200,630,false],"landscape":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/05.jpg",1200,630,false],"portraits":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/05.jpg",1200,630,false],"thumbnail":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/05-150x150.jpg",150,150,true],"medium":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/05-300x158.jpg",300,158,true],"large":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/05-1024x538.jpg",1024,538,true],"1536x1536":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/05.jpg",1200,630,false],"2048x2048":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/05.jpg",1200,630,false],"trp-custom-language-flag":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/05-18x9.jpg",18,9,true],"woocommerce_thumbnail":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/05-300x300.jpg",300,300,true],"woocommerce_single":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/05-600x315.jpg",600,315,true],"woocommerce_gallery_thumbnail":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/05-100x100.jpg",100,100,true]},"rttpg_author":{"display_name":"","author_link":"https:\/\/droneth.or.th\/en\/author\/"},"rttpg_comment":0,"rttpg_category":"<a href=\"https:\/\/droneth.or.th\/en\/category\/cybersecurity\/\" rel=\"category tag\">Cybersecurity<\/a> <a href=\"https:\/\/droneth.or.th\/en\/category\/cybersecurity\/zero-day-vulnerability\/\" rel=\"category tag\">Zero-Day \u0e41\u0e25\u0e30\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48<\/a>","rttpg_excerpt":"\u0e40\u0e08\u0e32\u0e30\u0e25\u0e36\u0e01 Oracle PeopleSoft Zero-Day CVE-2026-35273 \u0e17\u0e35\u0e48 ShinyHunters \u0e43\u0e0a\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e20\u0e32\u0e04\u0e01\u0e32\u0e23\u0e28\u0e36\u0e01\u0e29\u0e32 \u0e1e\u0e23\u0e49\u0e2d\u0e21\u0e41\u0e01\u0e49\u0e04\u0e27\u0e32\u0e21\u0e40\u0e02\u0e49\u0e32\u0e43\u0e08\u0e40\u0e23\u0e37\u0e48\u0e2d\u0e07 100 \u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23, 68%, \u0e27\u0e34\u0e18\u0e35\u0e15\u0e23\u0e27\u0e08\u0e2a\u0e2d\u0e1a\u0e41\u0e25\u0e30\u0e41\u0e19\u0e27\u0e17\u0e32\u0e07\u0e1b\u0e49\u0e2d\u0e07\u0e01\u0e31\u0e19","_links":{"self":[{"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/posts\/18392","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/comments?post=18392"}],"version-history":[{"count":1,"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/posts\/18392\/revisions"}],"predecessor-version":[{"id":18409,"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/posts\/18392\/revisions\/18409"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/media\/18424"}],"wp:attachment":[{"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/media?parent=18392"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/categories?post=18392"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/tags?post=18392"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}