CYBERSECURITYTRACKER
TRACKING7,931 stories in this site build1,728 vulnerability news stories in this site build
Permanent story citation

ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8632

As cited

Copy frozen at (site build).

threat intel

ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

Mandiant and Google Threat Intelligence Group identified a renewed mass exploitation campaign by UNC6240 (ShinyHunters) targeting Oracle PeopleSoft using CVE-2026-35273, a critical vulnerability with CVSS 9.8. The threat actor modified its exploit to bypass web application firewall rules by URL-encoding the vulnerable PSEMHUB endpoint path, then deployed web shells, trojanized backdoors, and tunneling toolkits across dozens of systems globally spanning higher education, technology, healthcare, and government sectors. Post-exploitation activity included credential theft, lateral movement, and data exfiltration, with evidence suggesting preparations for extortion.

Why it matters: Organizations running unpatched Oracle PeopleSoft face immediate compromise risk from active exploitation; even those with web application firewall rules blocking PSEMHUB are vulnerable to the percent-encoded bypass technique and must apply the patch and validate defenses today.

VendorsMicrosoftGoogleOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

Mandiant and Google Threat Intelligence Group identified a renewed mass exploitation campaign by UNC6240 (ShinyHunters) targeting Oracle PeopleSoft using CVE-2026-35273, a critical vulnerability with CVSS 9.8. The threat actor modified its exploit to bypass web application firewall rules by URL-encoding the vulnerable PSEMHUB endpoint path, then deployed web shells, trojanized backdoors, and tunneling toolkits across dozens of systems globally spanning higher education, technology, healthcare, and government sectors. Post-exploitation activity included credential theft, lateral movement, and data exfiltration, with evidence suggesting preparations for extortion.

Why it matters: Organizations running unpatched Oracle PeopleSoft face immediate compromise risk from active exploitation; even those with web application firewall rules blocking PSEMHUB are vulnerable to the percent-encoded bypass technique and must apply the patch and validate defenses today.

VendorsGoogleMicrosoftOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

Mandiant and Google Threat Intelligence Group identified a renewed mass exploitation campaign by UNC6240 (ShinyHunters) targeting Oracle PeopleSoft using CVE-2026-35273, a critical vulnerability with CVSS 9.8. The threat actor modified its exploit to bypass web application firewall rules by URL-encoding the vulnerable PSEMHUB endpoint path, then deployed web shells, trojanized backdoors, and tunneling toolkits across dozens of systems globally spanning higher education, technology, healthcare, and government sectors. Post-exploitation activity included credential theft, lateral movement, and data exfiltration, with evidence suggesting preparations for extortion.

Why it matters: Organizations running unpatched Oracle PeopleSoft face immediate compromise risk from active exploitation; even those with web application firewall rules blocking PSEMHUB are vulnerable to the percent-encoded bypass technique and must apply the patch and validate defenses today.

VendorsGoogleMicrosoftOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

Mandiant and Google Threat Intelligence Group identified a renewed mass exploitation campaign by UNC6240 (ShinyHunters) targeting Oracle PeopleSoft using CVE-2026-35273, a critical vulnerability with CVSS 9.8. The threat actor modified its exploit to bypass web application firewall rules by URL-encoding the vulnerable PSEMHUB endpoint path, then deployed web shells, trojanized backdoors, and tunneling toolkits across dozens of systems globally spanning higher education, technology, healthcare, and government sectors. Post-exploitation activity included credential theft, lateral movement, and data exfiltration, with evidence suggesting preparations for extortion.

Why it matters: Organizations running unpatched Oracle PeopleSoft face immediate compromise risk from active exploitation; even those with web application firewall rules blocking PSEMHUB are vulnerable to the percent-encoded bypass technique and must apply the patch and validate defenses today.

VendorsGoogleMicrosoftOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary