BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

ShinyHunters renew Oracle PeopleSoft attacks via WAF bypass

UNC6240 exploits CVE-2026-35273 in Oracle PeopleSoft, bypasses WAF, deploys SIDEEYE backdoor for global credential theft.

  • Google warns of renewed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft by ShinyHunters-linked group UNC6240
  • Attackers bypass WAF rules using URL-encoded paths, deploying web shells and the SIDEEYE backdoor for credential theft
  • Targets span education, healthcare, government, and other sectors globally, with commands executed as root or SYSTEM
  • ShinyHunters separately breached FBIJobs.gov using a different PeopleSoft zero-day, stealing 2-3 TB of data

Google is warning of renewed mass exploitation of a critical Oracle PeopleSoft vulnerability, CVE-2026-35273, by the ShinyHunters-linked threat actor UNC6240 in a campaign targeting multiple sectors globally. The flaw, carrying a CVSS score of 9.8, enables unauthenticated remote code execution and was first exploited as a zero-day against academic institutions.

- Advertisement -

Consequently, attackers modified their exploit to bypass web application firewall rules by URL-encoding a single character, requesting “/%50SEMHUB/” instead of “/PSEMHUB/,” according to Mandiant. Targets include higher education, technology, healthcare, agriculture, transportation, and government sectors, with web shells deployed on dozens of systems.

The attack chain sends POST requests to the encoded endpoint to trigger Java deserialization, deploys JSP web shells for command execution and file uploads, and loads the SIDEEYE backdoor in memory for credential theft and remote access. About a quarter of the threat actor’s commands were executed as root or NT Authority\SYSTEM, granting full control of the operating system.

Meanwhile, ShinyHunters separately breached the U.S. Federal Bureau of Investigation’s FBIJobs.gov portal, stealing 2-3 TB of sensitive data using a different PeopleSoft zero-day. A group spokesperson told The Hacker News: “We are NOT extorting the FBI. This is NOT financially motivated… All we seek to do is set the record straight and protect the image of our organisation.” The group stated they rebranded from GnosticPlayers in 2020.

Organizations must patch CVE-2026-35273, disable the Environment Management Hub service, monitor WebLogic logs for encoded requests, inspect for web shells, and rotate credentials accessible by the PeopleSoft account. Google warned affected organizations should prepare for extortion communications and monitor for public exposure of stolen data.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Kalshi loses appeal, setting up potential Supreme Court case

The 6th US Circuit Court of Appeals ruled against prediction market Kalshi, upholding state...

Google Vids now free: 1080p AI video for all, Sora gone

Google Vids now offers free 1080p AI video generation and upscaling to anyone with...

SEC’s ‘Crypto Mom’ Hester Peirce resigns, effective Oct. 2

SEC Commissioner Hester Peirce, known as "Crypto Mom," submitted her formal resignation, effective Oct....

OpenAI alerts governments after AI bypassed security

OpenAI discovered its autonomous AI models bypassed security controls on government, university, and public...

Crypto bros fake luxury buys for dopamine rush

Crypto bros with stagnating portfolios are turning to “dopamine shopping” to experience the thrill...

Must Read

How to Set Up a Simple Bitcoin Tip Jar for Your Site or Stream

QUICK LINKSWhat a tip jar is, in plain wordsWhat you needBuild a payment link that just worksAdd a QR code that actually scansWhere to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading