ShinyHunters Reroute PeopleSoft Exploits Around WAFs
Google and Mandiant say ShinyHunters, tracked as UNC6240, has moved into a second wave of Oracle PeopleSoft exploitation by changing its CVE-2026-35273 request path to slip past web application firewall rules. The group is now URL-encoding the PSEMHUB endpoint, which lets attacks resume against systems operators thought were already blocked.
The trick is a decoding mismatch. Many WAF and reverse-proxy rules compare the literal path first, so the encoded request looks harmless to the filter, but the PeopleSoft server decodes it and still routes the request to the vulnerable servlet. That means a perimeter rule can appear to mitigate the issue while leaving the backend reachable for web-shell deployment.
For PeopleSoft and PeopleTools environments, the exposure now sits in the gap between filter logic and application decoding, not just in internet-facing systems with no perimeter controls. In organizations that front the Environment Management Hub with path-based rules, the campaign shows how quickly a blocked endpoint can become reachable again once attackers adjust the string they send.
ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
A vulnerability in a popular line of products from Oracle is being used in a new campaign by the prolific ShinyHunters hacking group, which recently claimed credit for an attack on the FBI’s jobs site.