[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$foG2b3-tAK2m7x0sYZAiICFiSqyEgeUbO6y0asKT95vA":3},{"article":4,"iocs":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"3aab4e91-4245-49fd-9368-78ed6e820531","ShinyHunters Bypass WAF Rules to Resume Oracle PeopleSoft Attacks","shinyhunters-bypass-waf-rules-to-resume-oracle-peoplesoft-attacks-70c80a","ShinyHunters exploit CVE-2026-35273 in Oracle PeopleSoft using URL encoding to bypass WAF rules, deploy web shells and spread the SIDEEYE backdoor.","The threat actor ShinyHunters (UNC6240) is actively exploiting CVE-2026-35273 in Oracle PeopleSoft, using URL encoding to bypass WAF protections. Attackers deploy web shells and the SIDEEYE backdoor, impacting various sectors including higher education, technology, and government.","ShinyHunters exploit CVE-2026-35273 in Oracle PeopleSoft using URL encoding to bypass WAF rules.","Security Cyber AttacksShinyHunters Bypass WAF Rules to Resume Oracle PeopleSoft Attacks ShinyHunters exploit CVE-2026-35273 in Oracle PeopleSoft using URL encoding to bypass WAF rules, deploy web shells and spread the SIDEEYE backdoor. byDeeba AhmedSeptember 26, 20262 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening Mandiant and the Google Threat Intelligence Group (GTIG) have identified renewed exploitation of a critical Oracle PeopleSoft vulnerability, with attackers using a simple URL trick to bypass web application firewall (WAF) rules deployed against the flaw. The activity is linked to UNC6240, aka ShinyHunters. The group exploited CVE-2026-35273 as a zero-day between May 27 and June 9. Oracle released an emergency security update on June 10; however, the latest activity is a continuation of this earlier campaign. URL Encoding Defeats WAF Rules The vulnerability affects PeopleSoft’s Environment Management Hub (PSEMHUB). In the latest campaign, attackers changed \u002FPSEMHUB\u002F to \u002F%50SEMHUB\u002F, replacing the letter “P” with its URL-encoded equivalent. For context, many WAF and reverse-proxy rules match the path before URL decoding, so they may not recognize the altered request. WebLogic then decodes the path and routes it to the vulnerable servlet, allowing exploitation to proceed. How URL encoding allows the request to bypass some WAF and proxy rules (Source: Google Threat Intelligence Group) Mandiant found web shells on dozens of compromised systems across higher education, technology, IT services, healthcare, agriculture, transportation and government. Hackread.com reported on the earlier campaign in June, when Mandiant and GTIG identified more than 100 organizations with potentially exposed PeopleSoft systems. 68% of the identified organizations were in higher education, with most of them based in the US. Web Shells and SIDEEYE Backdoor After exploitation, attackers deployed JSP web shells including x.jsp and u.jsp inside the PeopleSoft application directory. The first provides command execution, while the second can upload larger files in 150 KB chunks to avoid HTTP request-size limits. On Windows systems, attackers also uploaded a 5.2 MB file named Ple64.exe, a trojanized Light Alloy media player installer that delivers the SIDEEYE backdoor. Mandiant found that the installer was signed with a valid certificate. SIDEEYE can steal browser and desktop application credentials, manage files and processes, and provide reverse-shell and reverse-proxy capabilities. Attackers also used the open-source Neo-reGeorg tunneling tool and legitimate MeshAgent remote-management software to maintain access to compromised environments. The findings come days after ShinyHunters told Hackread.com that it used an Oracle PeopleSoft zero-day to gain initial access to the FBI through its job application portal. The group said it then moved laterally into other FBI systems, including AWS GovCloud infrastructure, and claimed to have downloaded between 2TB and 3TB of data. ShinyHunters did not identify the PeopleSoft vulnerability used against the FBI as CVE-2026-35273, and there is currently no evidence linking the FBI intrusion to the vulnerability described in Mandiant’s latest research. Patch Instead of Relying on WAF Rules Mandiant recommends applying Oracle’s security update rather than relying on WAF filtering. Organizations should also disable the Environment Management Hub where possible, inspect WebLogic logs for normal and encoded \u002FPSEMHUB\u002F requests, check the PeopleSoft application directory for unexpected JSP or executable files, and rotate credentials accessible from compromised systems. Deeba Ahmed Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage. View Posts Cyber AttackCyber CrimeCybersecurityGoogleGTIGMandiantOraclePeopleSoftShinyHuntersVulnerabilityWAF Leave a Reply Cancel reply View Comments (0) Related Posts Read More Security Technology Kaspersky Willing to Share Its Source Code with US Govt Eugene Kaspersky, the CEO of Kaspersky Labs, is ready to share the source code of the software that… byJahanzaib Hassan Read More Security Cyber Attacks Cyber Crime Dark Web Trellix Details DarkSword, JSCeal, Axios npm Attack and APT28 Campaigns DarkSword, JSCeal, Axios, Bitter APT, and APT28 campaigns reveal evolving tactics targeting iPhones, Southeast Asia, software supply chains, diplomatic organizations, and European governments. byDeeba Ahmed Read More Crypto BlackBerry Security Crypto Industry Lost $685 Million in Q3 2023, 30% by Lazarus Group Immunefi Crypto Losses Report: Q3 2023 Sees Highest Losses of the Year. byWaqas Read More Security Malware Surveillance Nearly 80 Sony IP Camera Models Plagued with Backdoor Accounts SEC Consult, renowned IT security services and consultation firm, has identified that there is a critical flaw in… byUzair Amir","https:\u002F\u002Fhackread.com\u002Fshinyhunters-bypass-waf-rules-oracle-peoplesoft-attacks\u002F","https:\u002F\u002Fhackread.com\u002Fwp-content\u002Fuploads\u002F2026\u002F09\u002Fshinyhunters-bypass-waf-rules-oracle-peoplesoft-attacks.jpg","2026-09-26T13:36:11+00:00","2026-09-26T20:00:19.001323+00:00",9,[18,21,23,26,29],{"name":19,"type":20},"ShinyHunters","threat_actor",{"name":22,"type":20},"UNC6240",{"name":24,"type":25},"Oracle PeopleSoft","product",{"name":27,"type":28},"Oracle","vendor",{"name":30,"type":31},"WAF","technology","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":32,"icon":34,"name":35,"slug":36},null,"Threat Intelligence","threat-intelligence",[38,43,48,53],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":49},{"id":50,"icon":34,"name":51,"slug":52},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":54},{"id":32,"icon":34,"name":35,"slug":36},[56,60,63,66,69],{"type":57,"value":58,"context":59},"cve","CVE-2026-35273","Vulnerability in Oracle PeopleSoft exploited by ShinyHunters.",{"type":52,"value":61,"context":62},"SIDEEYE","Backdoor deployed by ShinyHunters.",{"type":52,"value":64,"context":65},"x.jsp","JSP web shell used for command execution.",{"type":52,"value":67,"context":68},"u.jsp","JSP web shell used for file uploads.",{"type":52,"value":70,"context":71},"Ple64.exe","Trojanized Light Alloy installer delivering SIDEEYE backdoor."]