Skip to main content
News Directory 3
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Menu
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
ShinyHunters Targets Oracle PeopleSoft in Mass Exploitation Campaign - News Directory 3

ShinyHunters Targets Oracle PeopleSoft in Mass Exploitation Campaign

September 29, 2026 Lisa Park Tech
News Context
At a glance
  • Google's cybersecurity unit notified more than 100 organizations about a renewed mass-exploitation campaign targeting CVE-2026-35273, a critical zero-day vulnerability in Oracle PeopleSoft.
  • The threat actor group, tracked by Mandiant as UNC6240, modified its exploitation strategy after organizations deployed string-based web application firewall rules as a stopgap instead of installing Oracle’s...
  • While initial campaigns in May and June of 2026 targeted primarily higher education institutions, the renewed activity has affected dozens of systems globally across sectors including technology, IT...
Original source: techradar.com

Google’s cybersecurity unit notified more than 100 organizations about a renewed mass-exploitation campaign targeting CVE-2026-35273, a critical zero-day vulnerability in Oracle PeopleSoft. Threat actors identified as ShinyHunters have bypassed web application firewall rules implemented by organizations that failed to apply Oracle’s software patch, expanding their attacks from higher education to technology, healthcare, government, and transportation sectors.

Bypassing Web Application Firewall Mitigations

The threat actor group, tracked by Mandiant as UNC6240, modified its exploitation strategy after organizations deployed string-based web application firewall rules as a stopgap instead of installing Oracle’s official updates. Mandiant and Google’s Threat Intelligence Group reported that the attackers bypassed these restrictions by using URL encoding on a single character in the request path, requesting /%50SEMHUB/ instead of the blocked /PSEMHUB/ endpoint. According to the joint threat report, many reverse proxies and web application firewalls evaluate literal paths prior to URL decoding, whereas the PeopleSoft application server decodes the request and routes it directly to the vulnerable servlet. This discrepancy allowed hackers to reach the Environment Management Hub (PSEMHUB) servlet on systems whose operators believed their network defenses had neutralized the risk.

Global Expansion and SIDEEYE Backdoor Deployment

While initial campaigns in May and June of 2026 targeted primarily higher education institutions, the renewed activity has affected dozens of systems globally across sectors including technology, IT services, healthcare, agriculture, transportation, and government. Google researchers noted that the SIDEEYE trojan is disguised as a Light Alloy media player installer, digitally signed with a valid certificate that has since been revoked. Once installed on a server, the backdoor enables credential theft, file and process management, reverse shell execution, and traffic proxying. ShinyHunters has also claimed responsibility for breaching FBI personnel data during the campaign, though the Federal Bureau of Investigation stated it is aggressively investigating the claims and noted issues with several online portals.

https://x.com/IntCyberDigest/status/2103629876322246660

Remediation Steps and Verification Guidance

Security researchers emphasize that Oracle’s original patch for CVE-2026-35273, released on June 10, 2026, remains fully effective against the underlying Java deserialization vulnerability, rendering the firewall bypass ineffective on fully updated systems. Mandiant and Google advise organizations to apply the security alert immediately, disable the Environment Management Hub service in multi-server setups, or remove the PSEMHUB application entirely in single-server environments. Administrators should review WebLogic access logs for requests directed to /PSEMHUB and any percent-encoded variants, inspect application directories for unauthorized files within the WAR archive, and rotate credentials accessible to the PeopleSoft application service account.

More on Targets Oracle

The Truth About the ShinyHunters Oracle PeopleSoft Zero-Day
Instagram
Instagram

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

More on this

  • Meta develops Muse Charm, a portable device for its AI assistant
  • Edouard Philippe proposes pension reform to age 65 and 45 years
  • Namibia Targets 1.8 Million Tourists in 2030 Growth Plan (time.news)

Related

Search:

News Directory 3

News Directory 3 catalogs US newspapers, news services, newsstands and digital news outlets across all 50 states. Browse local publishers by city, state, or topic, and follow current headlines linked back to their original sources.

Quick Links

  • Disclaimer
  • Terms and Conditions
  • About Us
  • Advertising Policy
  • Contact Us
  • Cookie Policy
  • Editorial Guidelines
  • Privacy Policy

Browse by State

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado

© 2026 News Directory 3. All rights reserved.
For contact, advertising, copyright, issues email: office@newsdirectory3.com