ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
ShinyHunters bypasses WAF rules blocking PeopleSoft CVE-2026-35273 via percent-encoding, resuming RCE attacks deploying web shells and SIDEEYE backdoors.
Mandiant and Google Threat Intelligence report ShinyHunters (UNC6240) is abusing percent-encoding ('/%50SEMHUB/') to evade WAF rules blocking the vulnerable '/PSEMHUB/' endpoint on unpatched Oracle PeopleSoft servers, because WebLogic decodes the path and routes it to the flaw. CVE-2026-35273 is an unauthenticated RCE previously used to steal data from 100 organizations. The new wave deployed JSP web shells on dozens of systems across education, healthcare, government, and other sectors, plus the SIDEEYE backdoor, Neo-reGeorg tunneling, and MeshAgent for persistence. ShinyHunters claims the same bypass was used against FBI Jobs along with a new unknown PSEMHUB zero-day.