Mandiant and Google Threat Intelligence Group (GTIG) issued a warning regarding a new mass-exploitation campaign by the ShinyHunters group, also tracked as UNC6240. This campaign specifically targets organizations using Oracle PeopleSoft, an enterprise resource planning (ERP) software suite for managing core business functions like finance, HR, and payroll.
The new wave of attacks stems from ShinyHunters modifying an exploit for a zero-day vulnerability in PeopleSoft, tracked as CVE-2026-35273. The modification allows the exploit to bypass web application firewall (WAF) rules that block the vulnerable Environment Management Hub (PSEMHUB) endpoint. This is achieved by using '%50', the URL-encoded form of 'P', in the request path containing '/PSEMHUB', which many WAFs fail to decode before matching rules.
While ShinyHunters' initial PeopleSoft campaign in June targeted over 100 customers, primarily in the education sector, the new attacks have expanded to include agriculture, government, healthcare, IT services, technology, and transportation organizations. Confirmed victims from the initial campaign include the University of Nottingham, NAIC, and Nissan.
As part of the new campaign, attackers deploy web shells on systems after bypassing WAFs. They use multiple POST requests to ensure web shell deployment across load-balanced environments or to directly execute commands and receive output in HTTP responses. The group establishes persistence using two single-line JSP web shells and deploys the SideEye backdoor on Windows systems.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Mandiant reports that the ShinyHunters hacking group is exploiting workarounds for a previously patched Oracle PeopleSoft vulnerability (CVE-2026-35273). The group is targeting organizations that implemented defensive guidance without applying the official patch, deploying web shells on systems across multiple sectors.
Mandiant and Google Threat Intelligence Group reported that the ShinyHunters group initiated a new mass-exploitation campaign targeting Oracle PeopleSoft customers. This campaign uses a modified exploit for CVE-2026-35273 to bypass web application firewalls (WAFs), expanding its targets beyond the education sector to various industries.