Decoding the world of cybersecurity

ShinyHunters bypasses PeopleSoft WAF controls

Google says ShinyHunters has renewed mass exploitation of a PeopleSoft vulnerability after modifying requests to evade web application firewall rules used as a temporary mitigation.

ShinyHunters bypasses PeopleSoft WAF controls
Summary
  • Mandiant and Google Threat Intelligence Group have identified renewed mass exploitation of CVE-2026-35273 by UNC6240, which they associate with ShinyHunters.
  • The attackers bypassed string-based WAF rules by URL-encoding a single character in the vulnerable PSEMHUB path.
  • Google says web shells have been deployed on dozens of systems across multiple sectors and warns that WAF controls are not a substitute for patching.

ShinyHunters has renewed mass exploitation of a critical Oracle PeopleSoft vulnerability after modifying attack requests to bypass web application firewall rules that some organisations had used as a temporary defence.

Google Threat Intelligence Group and Mandiant said UNC6240, which they associate with ShinyHunters, has expanded exploitation of CVE-2026-35273 across multiple sectors and geographies.

The vulnerability affects Oracle PeopleSoft and was previously exploited as a zero-day between 27 May and 9 June, primarily against higher-education organisations. Oracle released an out-of-band security alert on 10 June.

The renewed campaign shows how a compensating control can lose effectiveness when it blocks a particular representation of an exploit rather than removing the vulnerable code underneath it.

In its latest analysis, Google said UNC6240 changed the request for the vulnerable PSEMHUB endpoint by URL-encoding a single character.

Instead of requesting the literal /PSEMHUB/ path, the attackers used /%50SEMHUB/. Google said many WAF and reverse-proxy rules matched the literal path before URL decoding, while the PeopleSoft application server decoded the modified request and continued routing it to the vulnerable servlet.

Google said the attackers had deployed web shells on dozens of systems globally across higher education, technology, IT services, healthcare, agriculture, transportation, and government.

The modification is technically small but operationally important. Organisations frequently deploy WAF rules when application patches cannot be installed immediately because of testing requirements, change-management constraints, legacy dependencies, or the operational risk associated with changing core systems.

Those controls can reduce exposure, but they remain an additional enforcement layer rather than a correction to the vulnerable application. If the rule relies on a known path or exploit representation, an attacker can search for an encoding that the defensive layer and backend interpret differently.

PeopleSoft environments can be particularly difficult to change quickly because they often support payroll, human resources, finance, procurement, and other core enterprise processes.

Google said the current campaign specifically demonstrates UNC6240 adapting to published defensive guidance and targeting organisations that deployed WAF rules without applying the underlying security update.

The researchers observed activity ranging from initial target verification through web-shell deployment and hands-on-keyboard activity. On compromised systems, some attacker commands were executed with root or NT Authority\SYSTEM privileges, while others ran under PeopleSoft or WebLogic service accounts with access to configuration files and application data.

Google’s attribution of UNC6240 to ShinyHunters is a threat-intelligence assessment rather than a formal finding by Oracle or law enforcement. It should consequently remain attributed to Google and Mandiant.

The incident gives practical weight to the distinction between mitigation and remediation. A WAF rule may reduce immediate risk while an organisation prepares an application update, but it does not eliminate the vulnerable component, and its effectiveness can change as attackers adapt.

Google recommends applying Oracle’s security update for CVE-2026-35273 and says WAF rules and path-based blocking are not substitutes for patching.

The renewed exploitation means organisations that treated the earlier WAF rule as an enduring control need to reassess both current exposure and evidence of compromise on systems that remained unpatched.

×