started · updated
ShinyHunters exploits Oracle PeopleSoft via WAF bypass
The threat group ShinyHunters (also known as UNC6240) has launched a renewed mass-exploitation campaign targeting Oracle PeopleSoft servers. The group is exploiting CVE-2026-35273, a critical vulnerability with a CVSS score of 9.8 that allows for unauthenticated remote code execution.
To evade security measures, the attackers have modified their tactics to bypass Web Application Firewalls (WAF). Instead of requesting the known vulnerable path '/PSEMHUB/', they use URL-encoding to request '/%50SEMHUB/'. This technique allows the requests to bypass string-matching rules in many WAFs, while the PeopleSoft application subsequently decodes the path and processes the malicious request.
Mandiant reports that the campaign has impacted dozens of systems globally across multiple sectors, including higher education, healthcare, technology, agriculture, transportation, and government. Following successful intrusions, the group has been observed deploying JSP web shells and the SIDEEYE backdoor to maintain persistence and execute commands.
Additionally, ShinyHunters has claimed responsibility for breaching FBI personnel data, allegedly exposing names and medical records of employees and applicants. The FBI has stated it is aggressively investigating these reports.
Entities
FBI · Google Mandiant · Oracle · PeopleSoft · ShinyHunters · UNC6240
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 9 SOURCES] The threat group ShinyHunters (UNC6240) is using URL-encoding to bypass Web Application Firewalls (WAF) when exploiting Oracle PeopleSoft. cyberinsider.com · www.blogspan.net · dev.to · www.archynewsy.com · www.it-boltwise.de · +3 more
- [● 2 SOURCES] The ShinyHunters group claimed to have stolen personal data belonging to FBI employees and applicants. www.archynewsy.com · sundayguardianlive.com
- [● 9 SOURCES] The vulnerability CVE-2026-35273 in Oracle PeopleSoft allows for unauthenticated remote code execution. www.archynewsy.com · cyberinsider.com · www.it-boltwise.de · www.blogspan.net · dev.to · +3 more
- [● 7 SOURCES] The exploitation campaign targets multiple sectors including higher education, healthcare, technology, agriculture, transportation, and government. www.archynewsy.com · cyberinsider.com · www.cryptopolitan.com · www.blogspan.net · dev.to · +2 more
- [● 7 SOURCES] Attackers bypass WAF rules by replacing the letter 'P' in the '/PSEMHUB/' path with its percent-encoded equivalent, '%50'. cyberinsider.com · www.blogspan.net · dev.to · www.archynewsy.com · www.it-boltwise.de · +1 more
- [● 4 SOURCES] Attackers have deployed JSP web shells and the SIDEEYE backdoor on compromised systems. cyberinsider.com · www.blogspan.net · dev.to · www.archynewsy.com