ShinyHunters Targets Oracle PeopleSoft in Mass Exploitation Campaign
- Google's cybersecurity unit notified more than 100 organizations about a renewed mass-exploitation campaign targeting CVE-2026-35273, a critical zero-day vulnerability in Oracle PeopleSoft.
- The threat actor group, tracked by Mandiant as UNC6240, modified its exploitation strategy after organizations deployed string-based web application firewall rules as a stopgap instead of installing Oracle’s...
- While initial campaigns in May and June of 2026 targeted primarily higher education institutions, the renewed activity has affected dozens of systems globally across sectors including technology, IT...
Google’s cybersecurity unit notified more than 100 organizations about a renewed mass-exploitation campaign targeting CVE-2026-35273, a critical zero-day vulnerability in Oracle PeopleSoft. Threat actors identified as ShinyHunters have bypassed web application firewall rules implemented by organizations that failed to apply Oracle’s software patch, expanding their attacks from higher education to technology, healthcare, government, and transportation sectors.
Bypassing Web Application Firewall Mitigations
The threat actor group, tracked by Mandiant as UNC6240, modified its exploitation strategy after organizations deployed string-based web application firewall rules as a stopgap instead of installing Oracle’s official updates. Mandiant and Google’s Threat Intelligence Group reported that the attackers bypassed these restrictions by using URL encoding on a single character in the request path, requesting /%50SEMHUB/ instead of the blocked /PSEMHUB/ endpoint. According to the joint threat report, many reverse proxies and web application firewalls evaluate literal paths prior to URL decoding, whereas the PeopleSoft application server decodes the request and routes it directly to the vulnerable servlet. This discrepancy allowed hackers to reach the Environment Management Hub (PSEMHUB) servlet on systems whose operators believed their network defenses had neutralized the risk.
Global Expansion and SIDEEYE Backdoor Deployment
While initial campaigns in May and June of 2026 targeted primarily higher education institutions, the renewed activity has affected dozens of systems globally across sectors including technology, IT services, healthcare, agriculture, transportation, and government. Google researchers noted that the SIDEEYE trojan is disguised as a Light Alloy media player installer, digitally signed with a valid certificate that has since been revoked. Once installed on a server, the backdoor enables credential theft, file and process management, reverse shell execution, and traffic proxying. ShinyHunters has also claimed responsibility for breaching FBI personnel data during the campaign, though the Federal Bureau of Investigation stated it is aggressively investigating the claims and noted issues with several online portals.
https://x.com/IntCyberDigest/status/2103629876322246660
Remediation Steps and Verification Guidance
Security researchers emphasize that Oracle’s original patch for CVE-2026-35273, released on June 10, 2026, remains fully effective against the underlying Java deserialization vulnerability, rendering the firewall bypass ineffective on fully updated systems. Mandiant and Google advise organizations to apply the security alert immediately, disable the Environment Management Hub service in multi-server setups, or remove the PSEMHUB application entirely in single-server environments. Administrators should review WebLogic access logs for requests directed to /PSEMHUB and any percent-encoded variants, inspect application directories for unauthorized files within the WAR archive, and rotate credentials accessible to the PeopleSoft application service account.
