ShinyHunters Reroute PeopleSoft Exploits Around WAFs
Google and Mandiant say ShinyHunters, tracked as UNC6240, has moved into a second wave of Oracle PeopleSoft exploitation by changing its CVE-2026-35273 request path to slip past web application firewall rules. The group is now URL-encoding the PSEMHUB endpoint, which lets attacks resume against systems operators thought were already blocked.
The trick is a decoding mismatch. Many WAF and reverse-proxy rules compare the literal path first, so the encoded request looks harmless to the filter, but the PeopleSoft server decodes it and still routes the request to the vulnerable servlet. That means a perimeter rule can appear to mitigate the issue while leaving the backend reachable for web-shell deployment.
For PeopleSoft and PeopleTools environments, the exposure now sits in the gap between filter logic and application decoding, not just in internet-facing systems with no perimeter controls. In organizations that front the Environment Management Hub with path-based rules, the campaign shows how quickly a blocked endpoint can become reachable again once attackers adjust the string they send.
A vulnerability in a popular line of products from Oracle is being used in a new campaign by the prolific ShinyHunters hacking group, which recently claimed credit for an attack on the FBI’s jobs site.
Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group.
Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters.
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.
This follow-up report details how UNC6240 (ShinyHunters) is mass-exploiting Oracle PeopleSoft (CVE-2026-35273) by bypassing WAF rules via a single URL-encoded character, providing full analysis of the attack pipeline, observed post-exploitation activity, IOCs, and remediation steps.