< Back to all clusters
[TECHNOLOGY] · United States · 11 sources

started · updated

ShinyHunters exploits Oracle PeopleSoft via WAF bypass

The threat group ShinyHunters (also known as UNC6240) has launched a renewed mass-exploitation campaign targeting Oracle PeopleSoft servers. The group is exploiting CVE-2026-35273, a critical vulnerability with a CVSS score of 9.8 that allows for unauthenticated remote code execution.

To evade security measures, the attackers have modified their tactics to bypass Web Application Firewalls (WAF). Instead of requesting the known vulnerable path '/PSEMHUB/', they use URL-encoding to request '/%50SEMHUB/'. This technique allows the requests to bypass string-matching rules in many WAFs, while the PeopleSoft application subsequently decodes the path and processes the malicious request.

Mandiant reports that the campaign has impacted dozens of systems globally across multiple sectors, including higher education, healthcare, technology, agriculture, transportation, and government. Following successful intrusions, the group has been observed deploying JSP web shells and the SIDEEYE backdoor to maintain persistence and execute commands.

Additionally, ShinyHunters has claimed responsibility for breaching FBI personnel data, allegedly exposing names and medical records of employees and applicants. The FBI has stated it is aggressively investigating these reports.

Entities

FBI · Google Mandiant · Oracle · PeopleSoft · ShinyHunters · UNC6240

Claims

What the coverage asserts, and how many sources carry each claim.