← All stories
● Covered by 2 sources · 2 reportsMedium impact2 negative

ShinyHunters Launches New Oracle PeopleSoft Exploitation Campaign Bypassing WAFs

🔄 Updated 3d ago — new reporting from The Record
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • ShinyHunters launched a new exploitation campaign against Oracle PeopleSoft customers.
  • The group modified an existing exploit (CVE-2026-35273) to bypass WAF rules.
  • The new campaign targets diverse sectors including agriculture, government, and healthcare.
  • Attackers deploy web shells and the SideEye backdoor on compromised systems.
  • Mandiant published a blog about the vulnerability on Friday.
  • ShinyHunters claimed credit for an attack on the FBI’s jobs site.
  • The vulnerability was disclosed in June.
  • Oracle released a patch on June 10.
  • Mandiant provided guidance on how organizations could install the patch or institute workarounds.
  • ShinyHunters exploited the bug as a zero-day between May 27 and June 9.
  • ShinyHunters previously attacked academic institutions.

New Exploitation Campaign Targets PeopleSoft

Mandiant and Google Threat Intelligence Group (GTIG) issued a warning regarding a new mass-exploitation campaign by the ShinyHunters group, also tracked as UNC6240. This campaign specifically targets organizations using Oracle PeopleSoft, an enterprise resource planning (ERP) software suite for managing core business functions like finance, HR, and payroll.

WAF Bypass Mechanism

The new wave of attacks stems from ShinyHunters modifying an exploit for a zero-day vulnerability in PeopleSoft, tracked as CVE-2026-35273. The modification allows the exploit to bypass web application firewall (WAF) rules that block the vulnerable Environment Management Hub (PSEMHUB) endpoint. This is achieved by using '%50', the URL-encoded form of 'P', in the request path containing '/PSEMHUB', which many WAFs fail to decode before matching rules.

Expanded Targeting and Tactics

While ShinyHunters' initial PeopleSoft campaign in June targeted over 100 customers, primarily in the education sector, the new attacks have expanded to include agriculture, government, healthcare, IT services, technology, and transportation organizations. Confirmed victims from the initial campaign include the University of Nottingham, NAIC, and Nissan.

As part of the new campaign, attackers deploy web shells on systems after bypassing WAFs. They use multiple POST requests to ensure web shell deployment across load-balanced environments or to directly execute commands and receive output in HTTP responses. The group establishes persistence using two single-line JSP web shells and deploys the SideEye backdoor on Windows systems.

Updates

🕒 2026-09-28 · new reporting from The Record
  • Mandiant published a blog about the vulnerability on Friday.
  • ShinyHunters claimed credit for an attack on the FBI’s jobs site.
  • The vulnerability was disclosed in June.
  • Oracle released a patch on June 10.
  • Mandiant provided guidance on how organizations could install the patch or institute workarounds.
  • ShinyHunters exploited the bug as a zero-day between May 27 and June 9.
  • ShinyHunters previously attacked academic institutions.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Mandiant reports that the ShinyHunters hacking group is exploiting workarounds for a previously patched Oracle PeopleSoft vulnerability (CVE-2026-35273). The group is targeting organizations that implemented defensive guidance without applying the official patch, deploying web shells on systems across multiple sectors.

Mandiant and Google Threat Intelligence Group reported that the ShinyHunters group initiated a new mass-exploitation campaign targeting Oracle PeopleSoft customers. This campaign uses a modified exploit for CVE-2026-35273 to bypass web application firewalls (WAFs), expanding its targets beyond the education sector to various industries.