Google says ShinyHunters has renewed "mass exploitation" of a flaw in Oracle's PeopleSoft; ShinyHunters has said it accessed FBI data using a flaw in PeopleSoft
First reported by Reuters ·
Web application firewall rules are now insufficient to protect against this exploit, requiring immediate patching.
Google Cloud's Mandiant and Threat Intelligence Group (GTIG) reported a renewed mass exploitation campaign by the threat actor UNC6240, also known as ShinyHunters, targeting Oracle's PeopleSoft. This campaign revisits CVE-2026-35273, a vulnerability initially exploited as a zero-day against academic institutions in June 2026. ShinyHunters has updated its exploit to bypass Web Application Firewall (WAF) rules by URL-encoding characters in the vulnerable PSEMHUB endpoint path, a technique that circumvents perimeter defenses that rely on literal path matching before URL decoding. The exploitation has expanded globally across higher education, technology, IT services, healthcare, agriculture, transportation, and government sectors, with web shells deployed on dozens of compromised systems. Mandiant urges organizations using PeopleSoft to immediately apply Oracle's security patch, disable the Environment Management Hub service if possible, and conduct thorough log and file system inspections for signs of compromise. They also advise rotating credentials associated with the PeopleSoft application service account.
The renewed exploitation of CVE-2026-35273 by ShinyHunters highlights a significant trend: threat actors are actively adapting to common defensive measures, specifically Web Application Firewalls (WAFs). By employing simple URL-encoding tricks to bypass WAF rules that previously offered a layer of protection, the actors demonstrate a sophisticated understanding of how network security appliances process requests. This bypass method effectively renders perimeter-based blocking insufficient, forcing organizations to rely on timely patching or complete service disablement for true security. The expanded targeting across numerous sectors indicates a broad-spectrum attack, suggesting that organizations in any industry utilizing Oracle PeopleSoft should consider themselves at risk.
This development signals a potential arms race between exploit creators and WAF vendors, where basic evasion techniques can quickly undermine established security postures. Companies that have relied on WAFs as a primary defense against known vulnerabilities may find themselves exposed, necessitating a more robust security strategy that includes diligent patching and active threat hunting. The ability for attackers to achieve fileless command execution and deploy sophisticated web shells underscores the need for deeper inspection capabilities and endpoint detection beyond simple file integrity checks. Organizations should also be wary of residual threats, such as unexpected remote access agents, which may indicate a persistent compromise.
AI-written summary. May contain errors.