ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
4 Articles
4 Articles
Oracle PeopleSoft Servers Targeted Again as ShinyHunters Expands Extortion Operations
The ShinyHunters-linked threat cluster tracked as UNC6240 has renewed mass exploitation of Oracle PeopleSoft servers vulnerable to CVE-2026-35273. Expanding beyond its earlier focus on higher education into technology, healthcare, government, transportation, agriculture, and IT services. The campaign demonstrates how quickly financially motivated actors can adapt when organizations rely on perimeter workarounds rather than applying vendor-issued
ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
ShinyHunters has renewed attacks against Oracle PeopleSoft systems by slipping past web application firewall protections and planting web shells. The campaign shows how a small change in an attack request can reopen exposure that administrators believed had been contained. The activity targets CVE-2026-35273, a critical PeopleSoft flaw previously used as a zero-day against universities. The […]
The Shinyhunters cybercrime group has significantly expanded its attacks on Oracle-Peoplesoft. Mandant and the Google Threat Intelligence Group are monitoring a renewed mass exploitation of the CVE-2026-35273 vulnerability. The attackers bypass existing web application firewalls (WAFs) and install web shells as well as other malicious software on compromised systems. While the vulnerability was initially used primarily against institutions from …
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium








