As cited
Copy frozen at (site build).
threat intel
ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
Mandiant and Google Threat Intelligence Group identified a renewed mass exploitation campaign by UNC6240 (ShinyHunters) targeting Oracle PeopleSoft using CVE-2026-35273, a critical vulnerability with CVSS 9.8. The threat actor modified its exploit to bypass web application firewall rules by URL-encoding the vulnerable PSEMHUB endpoint path, then deployed web shells, trojanized backdoors, and tunneling toolkits across dozens of systems globally spanning higher education, technology, healthcare, and government sectors. Post-exploitation activity included credential theft, lateral movement, and data exfiltration, with evidence suggesting preparations for extortion.
Why it matters: Organizations running unpatched Oracle PeopleSoft face immediate compromise risk from active exploitation; even those with web application firewall rules blocking PSEMHUB are vulnerable to the percent-encoded bypass technique and must apply the patch and validate defenses today.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
Mandiant and Google Threat Intelligence Group identified a renewed mass exploitation campaign by UNC6240 (ShinyHunters) targeting Oracle PeopleSoft using CVE-2026-35273, a critical vulnerability with CVSS 9.8. The threat actor modified its exploit to bypass web application firewall rules by URL-encoding the vulnerable PSEMHUB endpoint path, then deployed web shells, trojanized backdoors, and tunneling toolkits across dozens of systems globally spanning higher education, technology, healthcare, and government sectors. Post-exploitation activity included credential theft, lateral movement, and data exfiltration, with evidence suggesting preparations for extortion.
Why it matters: Organizations running unpatched Oracle PeopleSoft face immediate compromise risk from active exploitation; even those with web application firewall rules blocking PSEMHUB are vulnerable to the percent-encoded bypass technique and must apply the patch and validate defenses today.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
Mandiant and Google Threat Intelligence Group identified a renewed mass exploitation campaign by UNC6240 (ShinyHunters) targeting Oracle PeopleSoft using CVE-2026-35273, a critical vulnerability with CVSS 9.8. The threat actor modified its exploit to bypass web application firewall rules by URL-encoding the vulnerable PSEMHUB endpoint path, then deployed web shells, trojanized backdoors, and tunneling toolkits across dozens of systems globally spanning higher education, technology, healthcare, and government sectors. Post-exploitation activity included credential theft, lateral movement, and data exfiltration, with evidence suggesting preparations for extortion.
Why it matters: Organizations running unpatched Oracle PeopleSoft face immediate compromise risk from active exploitation; even those with web application firewall rules blocking PSEMHUB are vulnerable to the percent-encoded bypass technique and must apply the patch and validate defenses today.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
Mandiant and Google Threat Intelligence Group identified a renewed mass exploitation campaign by UNC6240 (ShinyHunters) targeting Oracle PeopleSoft using CVE-2026-35273, a critical vulnerability with CVSS 9.8. The threat actor modified its exploit to bypass web application firewall rules by URL-encoding the vulnerable PSEMHUB endpoint path, then deployed web shells, trojanized backdoors, and tunneling toolkits across dozens of systems globally spanning higher education, technology, healthcare, and government sectors. Post-exploitation activity included credential theft, lateral movement, and data exfiltration, with evidence suggesting preparations for extortion.
Why it matters: Organizations running unpatched Oracle PeopleSoft face immediate compromise risk from active exploitation; even those with web application firewall rules blocking PSEMHUB are vulnerable to the percent-encoded bypass technique and must apply the patch and validate defenses today.
- Source published
- First seen by Cybersecurity Tracker