ShinyHunters renews attacks on unpatched PeopleSoft systems
ShinyHunters has resumed large-scale attacks on unpatched Oracle PeopleSoft systems, using encoded web addresses to evade some web application firewall rules and reach a known vulnerability, Google’s Mandiant threat-intelligence unit says. Mandiant reported dozens of affected systems worldwide across sectors including higher education, technology, health care, agriculture, transportation and government. It did not identify the organizations. The campaign targets systems vulnerable to CVE-2026-35273, an Oracle PeopleSoft flaw that allows unauthenticated remote code execution. Mandiant said the attackers focused on organizations that had added firewall rules to block the exposed PSEMHUB endpoint but had not installed Oracle’s security update. The reports do not provide an independently verified count of successful compromises among the systems observed. The bypass exploits a difference in how some firewalls and Oracle WebLogic process web addresses. Mandiant said attackers sent requests with percent-encoded versions of the PSEMHUB path, including a form in which “%50” represents the letter P.