Cybersecurity group ShinyHunters has reignited attacks on Oracle PeopleSoft platforms, cleverly evading web application firewall (WAF) defenses to deploy web shells. This maneuver exposes a vulnerability in CVE-2026-35273, a critical flaw that had been previously exploited, posing significant risks to multiple sectors.
Escalating Attacks on Multiple Industries
Initially targeting universities, the attackers have now broadened their scope to include sectors such as technology, healthcare, agriculture, and government. This expansion highlights the critical nature of the PeopleSoft vulnerability, as it endangers systems containing sensitive HR, payroll, and operational data.
Google Cloud’s security analysts have linked these renewed attacks to the group known as UNC6240, or ShinyHunters. According to a report shared with Cyber Security News, web shells were placed on numerous systems worldwide, indicating an extensive exploitation effort.
Technical Exploitation Tactics
The attackers effectively bypassed existing WAF protections by altering the request path encoding. This discrepancy between the encoding and the application server’s processing allowed malicious requests to bypass security measures. Once a system’s vulnerability was confirmed, attackers could either install JSP-based web shells or execute commands directly in memory, thereby avoiding detection by file-based security tools.
ShinyHunters utilized POST requests with serialized Java objects to identify potential targets. Even unsuccessful attempts provided valuable reconnaissance data, underscoring the need for thorough log reviews and analysis, especially in environments using load balancing.
Mitigation and Future Outlook
To counteract these threats, organizations must promptly apply security patches for CVE-2026-35273 and maintain updated PeopleTools versions. Disabling or removing unnecessary applications, such as the Environment Management Hub, further reduces risk. The necessity for rapid patching in internet-facing deployments is emphasized by the Oracle emergency security update.
Security teams are advised to scrutinize access logs for encoded routes and suspect external POST activities, and to monitor PeopleSoft web directories for unauthorized files. Affected organizations must prepare for potential data-theft extortion and conduct detailed audits of database access for any suspicious bulk exports.
The persistence of these attacks highlights the importance of treating detected web shells as indicators of full system compromise. By maintaining vigilance and implementing robust security measures, organizations can better protect against ongoing cybersecurity threats.
