- Google warns of renewed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft by ShinyHunters-linked group UNC6240
- Attackers bypass WAF rules using URL-encoded paths, deploying web shells and the SIDEEYE backdoor for credential theft
- Targets span education, healthcare, government, and other sectors globally, with commands executed as root or SYSTEM
- ShinyHunters separately breached FBIJobs.gov using a different PeopleSoft zero-day, stealing 2-3 TB of data
Google is warning of renewed mass exploitation of a critical Oracle PeopleSoft vulnerability, CVE-2026-35273, by the ShinyHunters-linked threat actor UNC6240 in a campaign targeting multiple sectors globally. The flaw, carrying a CVSS score of 9.8, enables unauthenticated remote code execution and was first exploited as a zero-day against academic institutions.
Consequently, attackers modified their exploit to bypass web application firewall rules by URL-encoding a single character, requesting “/%50SEMHUB/” instead of “/PSEMHUB/,” according to Mandiant. Targets include higher education, technology, healthcare, agriculture, transportation, and government sectors, with web shells deployed on dozens of systems.
The attack chain sends POST requests to the encoded endpoint to trigger Java deserialization, deploys JSP web shells for command execution and file uploads, and loads the SIDEEYE backdoor in memory for credential theft and remote access. About a quarter of the threat actor’s commands were executed as root or NT Authority\SYSTEM, granting full control of the operating system.
Meanwhile, ShinyHunters separately breached the U.S. Federal Bureau of Investigation’s FBIJobs.gov portal, stealing 2-3 TB of sensitive data using a different PeopleSoft zero-day. A group spokesperson told The Hacker News: “We are NOT extorting the FBI. This is NOT financially motivated… All we seek to do is set the record straight and protect the image of our organisation.” The group stated they rebranded from GnosticPlayers in 2020.
Organizations must patch CVE-2026-35273, disable the Environment Management Hub service, monitor WebLogic logs for encoded requests, inspect for web shells, and rotate credentials accessible by the PeopleSoft account. Google warned affected organizations should prepare for extortion communications and monitor for public exposure of stolen data.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
