ShinyHunters revives Oracle PeopleSoft attacks with a one-character firewall bypass
Google Cloud's Mandiant unit says the extortion group tracked as UNC6240 is exploiting a months-old, already-patched PeopleSoft flaw by URL-encoding a single character to slip past firewall rules meant to block it, hitting systems across seven industry sectors.

The extortion group known as ShinyHunters is running a renewed campaign against Oracle PeopleSoft servers worldwide, using a one-character trick to slip past firewalls that administrators believed had already closed off the attack, according to a threat intelligence report published by Google Cloud's Mandiant unit. The group, which Mandiant tracks as UNC6240, has planted web shells and a trojanized backdoor on dozens of PeopleSoft systems across higher education, technology, healthcare, agriculture, transportation and government networks in the past several weeks.
The vulnerability itself is not new. Oracle disclosed and patched it in June under the identifier CVE-2026-35273, an unauthenticated remote-code-execution flaw in PeopleSoft's Environment Management Hub component that the National Vulnerability Database rates at the maximum 9.8 severity score. What has changed, Mandiant says, is that the attackers have adapted to the defenses many organizations put up instead of patching, reviving a months-old zero-day into what security researchers call an "n-day" campaign against the unpatched majority.
How the bypass works
PeopleSoft administrators who could not immediately apply Oracle's patch were told in June to block external requests to the vulnerable endpoint, a path called /PSEMHUB/, at the network perimeter. Many did so through web application firewall rules that scan incoming requests for that literal text string. UNC6240's new technique defeats that defense with a single substitution: sending requests to /%50SEMHUB/ instead, where "%50" is the URL-encoded hexadecimal value for the letter "P."
Most firewall and reverse-proxy rules compare the request path as written, before it is decoded. Oracle's WebLogic application server, however, decodes the address and routes the traffic to the same vulnerable servlet regardless. The result is that a defense administrators believed had closed the door was, in practice, still open.
Once inside, Mandiant found, the attackers deployed a sequence of Java web shells — tracked as x.jsp, u.jsp and u2.jsp — to run commands and upload larger tools. On Windows servers, that included a 5.2-megabyte binary called Ple64.exe, tracked as SIDEEYE, disguised as an installer for the Light Alloy media player and signed with a valid certificate that Mandiant says it has asked the issuing authority, Sectigo, to revoke. The backdoor gives the attackers credential theft, file management and reverse-shell capabilities over separate control and data channels. On Linux hosts, the group used a legitimate remote-management tool along with a tunneling utility called Neo-reGeorg to move through networks undetected.
The scope and the stakes
Mandiant's researchers said a quarter of the post-exploitation commands they observed across compromised instances ran with root or Windows SYSTEM privileges, meaning the attackers achieved full control of the underlying operating system on many of the machines they hit, not merely access to PeopleSoft's application data. PeopleSoft is widely used to run human-resources, payroll and student-records systems, which puts sensitive personal and financial data for employees and students at risk on affected networks.
Organizations that identify a web shell should treat the host as compromised, preserve evidence, and rotate all credentials accessible from the PeopleSoft tier, prioritizing hosts where the WebLogic service runs as root or SYSTEM.
That guidance, from Mandiant's report, reflects the group's established pattern. UNC6240 has a documented history of stealing data and then threatening victims with public release on a leak site unless a ransom is paid, and Mandiant is telling affected organizations to prepare for extortion contact rather than assume the intrusion ends with removal of a web shell.
From a spring zero-day to a fall reboot
Mandiant first disclosed UNC6240's exploitation of the PeopleSoft flaw in June, after observing zero-day attacks against higher-education institutions between May 27 and June 9. Oracle responded with an out-of-band security alert and patch on June 10, and Mandiant's initial guidance told administrators who could not patch immediately to block traffic to the vulnerable endpoint at the network edge. The new campaign shows the group studying that public defensive advice and building around it: rather than moving on to new targets, UNC6240 went back after organizations that had put up a firewall rule but never applied the actual fix.
The pattern echoes earlier waves of PeopleSoft, MOVEit and other enterprise-software exploitation that has made data-theft extortion groups a persistent threat to institutions running older, internet-facing business applications. It also illustrates a narrower, recurring problem in web security, one that outlets tracking the campaign have noted applies well beyond PeopleSoft: firewalls that inspect literal request paths without first normalizing them can be bypassed by any encoding a downstream server is willing to decode, a category of flaw security researchers have flagged for years across many products.
Who is affected, and what comes next
Mandiant said the current wave has hit organizations across seven sectors — higher education, technology, IT services, healthcare, agriculture, transportation and government — and cautioned that the specific "%50" substitution is only one of many encoded or mixed-case variants of the endpoint path that could achieve the same bypass, meaning organizations relying on narrowly written firewall signatures should not consider themselves protected even after blocking that exact string.
The company's recommended response for administrators running PeopleSoft is direct: apply Oracle's June patch if it has not already been installed, disable the Environment Management Hub service where it is not needed, and treat WAF rules as a stopgap rather than a substitute for patching. Mandiant also published a set of indicators of compromise, including command-and-control server addresses and a file hash for the SIDEEYE backdoor, to help network defenders search their own logs for signs of the intrusion. Oracle's advisory continues to list PeopleTools versions 8.61 and 8.62 as affected.
For now, the campaign underscores a recurring gap between disclosure and remediation in enterprise software: a patch that has been public for more than three months is still being actively exploited, not because the fix does not work, but because a subset of administrators substituted a firewall rule for it — a substitution this campaign was specifically built to defeat.
OpenAI still probing scope of rogue AI agent incidents after image leak
Jury orders Apple to pay $5.7 billion in largest patent verdict in U.S. history

Researchers Find 16,000 Exposed Databases Behind AI-Built Apps
