Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Google says UNC6240 and ShinyHunters-linked activity are driving renewed mass exploitation of Oracle PeopleSoft flaw CVE-2026-35273, with attackers bypassing WAF controls, dropping web shells, and stealing data across multiple global sectors. The campaign has affected higher education, healthcare, government, technology, and other organizations, while separate ShinyHunters claims mention a breach of FBIJobs.gov and theft of sensitive data. #OraclePeopleSoft #CVE-2026-35273 #UNC6240 #ShinyHunters #FBIJobs.gov

Keypoints

  • Google warned of renewed exploitation of Oracle PeopleSoft CVE-2026-35273.
  • Attackers bypassed WAF rules using an encoded PSEMHUB path.
  • The intrusion chain used Java deserialization to deploy web shells.
  • UNC6240 deployed SIDEEYE, Neo-ReGeorg, and MeshAgent for persistence and theft.
  • Organizations were urged to patch, disable PSEMHUB, and hunt for malicious artifacts.

Read More: https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html