www.securityweek.com 28 Sept 2026, 10:56 UTC

ShinyHunters Revive Attacks on PeopleSoft with WAF Bypass

ShinyHunters Revive Attacks on PeopleSoft with WAF Bypass
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor

MANDIANT and the Google Threat Intelligence Group (GTIG) have warned that the ShinyHunters extortion group, tracked by Google as UNC6240, is conducting a fresh mass-exploitation campaign against Oracle PeopleSoft customers. PeopleSoft is used by large organisations for functions including finance, human resources, payroll and supply-chain management.

The activity follows a campaign in June that targeted more than 100 customers, with confirmed victims including the University of Nottingham, the National Association of Insurance Commissioners and Nissan.

The attackers are exploiting CVE-2026-35273, a PeopleSoft vulnerability that enables unauthenticated remote code execution. According to Mandiant and GTIG, UNC6240 has modified its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub endpoint. Requests containing “/PSEMHUB” use “%50”, the URL-encoded form of “P”, which can evade controls that inspect the path before decoding while the PeopleSoft server routes the decoded request to the vulnerable servlet.

The new campaign has reached organisations in agriculture, government, healthcare, IT services, technology and transport, and has resulted in web shells being installed on dozens of systems.

Investigators observed JSP web shells, the SideEye backdoor on Windows servers, and the Neo-reGeorg tunnelling toolkit and MeshCentral remote-management platform. The tools supported credential theft, file and process management, internal discovery, lateral movement and remote access. Attackers also abused PeopleSoft and WebLogic service accounts and ran commands with root or System privileges.

PeopleSoft customers are advised to apply Oracle’s patches for CVE-2026-35273, harden deployments, search for indicators of compromise and data theft, and prepare for possible extortion. Google said claims that ShinyHunters used a new zero-day may instead relate to this modified exploit.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline