ShinyHunters is using a URL-encoding trick to bypass WAF rules and keep exploiting Oracle PeopleSoft CVE-2026-35273 on unpatched servers. The group is deploying web shells and backdoors to steal data, move laterally, and maintain access across multiple sectors, including higher education and government. #ShinyHunters #UNC6240 #OraclePeopleSoft #CVE-2026-35273 #SIDEEYE #Neo-reGeorg #MeshAgent
Keypoints
- ShinyHunters is bypassing WAF rules by using encoded paths like /%50SEMHUB/.
- The technique lets the group keep exploiting Oracle PeopleSoft CVE-2026-35273.
- Google says the attacks are hitting education, technology, healthcare, and government targets.
- ShinyHunters uses web shells, SIDEEYE, Neo-ReGeorg, and MeshAgent to expand access.
- Mandiant advises patching PeopleSoft and checking logs for encoded PSEMHUB requests.