Back
Google: ShinyHunters renews mass exploitation of Oracle PeopleSoft flaw
SiTech AI Team2 წთ. საკითხავი

Google: ShinyHunters renews mass exploitation of Oracle PeopleSoft flaw

Mandiant says the hacking group adapted its exploit to get around web application firewall rules and hit dozens of systems worldwide, after a summer wave that mainly struck universities.

A renewed campaign

Google's cybersecurity unit said on Friday that the hacking group ShinyHunters has renewed "mass exploitation" of a flaw in Oracle's PeopleSoft software, after skirting defenses set up following summer attacks.

The finding was published by Mandiant and the Google Threat Intelligence Group. It came days after ShinyHunters said it had stolen FBI personnel data, a claim Reuters has not been able to corroborate.

PSEMHUB WAF bypass

How the defenses were bypassed

In the earlier wave, from May 27 to June 9, ShinyHunters exploited a critical remote code execution flaw in PeopleSoft's Environment Management Hub component, tracked as CVE-2026-35273 and rated 9.8 on the CVSS scale. The vulnerability was then a zero-day, and Oracle issued a security alert on June 10. Google notified more than 100 organizations, 68% of them in higher education.

According to Mandiant, the hackers changed their approach and targeted organizations that had deployed web application firewall (WAF) rules but had not applied Oracle's patch. They URL-encoded a single character in the request path, sending /%50SEMHUB/ instead of /PSEMHUB/. Many WAF and reverse proxy rules match the literal path before decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet.

ShinyHunters leak site post listing a PeopleSoft victim

Dozens of systems worldwide

Mandiant said the latest wave affected dozens of systems globally, in sectors ranging from higher education and technology to IT services, healthcare, agriculture, transportation and government.

The hackers placed web shells such as x.jsp and u.jsp in the PSEMHUB.war directory, or ran commands without leaving traces on disk. In some intrusions they uploaded a trojanized 5.2 MB installer, Ple64.exe, which loads a backdoor tracked as SIDEEYE.

What Mandiant recommends

Mandiant's advice is blunt: WAF rules and path blocking are not a substitute for patching. The company recommends applying Oracle's security alert, disabling the Environment Management Hub service where it is not needed, and searching WebLogic logs for requests to /PSEMHUB/ and its encoded variants. About a quarter of the commands observed on compromised hosts ran with root or SYSTEM privileges.

Oracle did not respond to requests for comment.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.