Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

ShinyHunters bypass Oracle PeopleSoft mitigations and resume attacks

ShinyHunters have bypassed security mitigations for a previously exploited Oracle PeopleSoft vulnerability and resumed attacks, according to a report from Mandiant and Google’s Threat Intelligence Group (GTIG). The activity has expanded beyond higher education to organizations in technology, IT services, healthcare, agriculture, transportation and government.

The flaw, CVE-2026-35273, affects the PeopleSoft Environment Management Hub (PSEMHUB) servlet. It stems from unsafe deserialization of Java objects and can enable remote code execution. Oracle fixed the vulnerability on June 10, 2026, in versions 8.61 and 8.62. CISA added it to its Known Exploited Vulnerabilities catalog on June 12 and set a three-day patching deadline for federal agencies.

Mandiant and GTIG say the attackers altered their exploit to evade web application firewall (WAF) rules. They URL-encoded one character in the request path, using /%50SEMHUB/ instead of /PSEMHUB/. The PeopleSoft server decodes the path and routes the request to the vulnerable servlet, even when a WAF rule checks the literal path before decoding.

The researchers reported web shells on “dozens of systems globally.” They say the attackers use the flaw to maintain access, steal credentials and extract sensitive data, including human resources or payroll files. Oracle’s vulnerability fix still addresses the flaw; the reported technique bypasses mitigations, not the patch. Mandiant and GTIG recommend applying Oracle’s security fix. They also list configuration-specific steps, log and file checks, credential rotation and monitoring outbound traffic as further actions for affected organizations.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.