ShinyHunters has launched another wave of attacks against Oracle PeopleSoft servers, finding a surprisingly simple way around defenses organizations deployed after the group began exploiting a critical vulnerability earlier this year.
Google’s Mandiant and Threat Intelligence Group have observed renewed mass exploitation of CVE-2026-35273, a critical PeopleSoft vulnerability that allows attackers to execute code remotely without authentication. ShinyHunters, tracked by Google as UNC6240, originally exploited the flaw as a zero-day between late May and early June.
Oracle released an emergency security update in June. Organizations unable to immediately patch were advised to block external access to the vulnerable PSEMHUB component using web application firewalls. ShinyHunters has now modified its requests to bypass some of those rules.
Instead of requesting the normal vulnerable path, the attackers encode a single character in the URL. Some firewalls check the request before decoding it and therefore fail to recognize the blocked path, while PeopleSoft later decodes the address and sends the request to the vulnerable component.
The technique has allowed ShinyHunters to resume attacks against systems where administrators relied on firewall rules rather than installing Oracle’s security update. Google has observed compromises across higher education, technology, IT services, healthcare, agriculture, transportation, and government organizations.
After gaining access, the attackers have installed web shells that provide remote control over compromised servers. Google also observed tunneling tools and the legitimate MeshAgent remote management software being deployed to maintain access. In some incidents, commands executed with root or SYSTEM privileges, providing complete control over the affected operating system.
Google says it has notified more than 100 organizations worldwide about activity associated with the renewed campaign.
The findings arrive shortly after ShinyHunters claimed responsibility for unauthorized activity involving the FBI’s recruitment website. The group says it accessed FBI systems through PeopleSoft and stole terabytes of information concerning employees and job applicants.
The FBI has confirmed that it is investigating unauthorized activity affecting FBIjobs.gov but has not confirmed ShinyHunters’ broader claims about stolen data or access to internal systems. The group also claims it exploited an additional unknown vulnerability in the same PeopleSoft component during the FBI incident.
