ShinyHunters PeopleSoft attacks are back. A one-letter WAF bypass lets the group exploit CVE-2026-35273 and plant web shells on unpatched servers.
#ShinyHunters #PeopleSoft #WAFBypass #CVE202635273 #UNC6240 #Oracle #DataExtortion #CyberSecurity

ShinyHunters PeopleSoft attacks are back. A one-letter WAF bypass lets the group exploit CVE-2026-35273 and plant web shells on unpatched servers.
#ShinyHunters #PeopleSoft #WAFBypass #CVE202635273 #UNC6240 #Oracle #DataExtortion #CyberSecurity
Google and Mandiant say ShinyHunters, tracked as UNC6240, is exploiting Oracle PeopleSoft at scale, bypassing WAF rules on PSEMHUB and deploying web shells, SideEye, Neo-ReGeorg, and MeshCentral for extortion. #ShinyHunters #OraclePeopleSoft #UNC6240
ShinyHunters is using URL encoding to bypass WAF rules and keep exploiting Oracle PeopleSoft CVE-2026-35273, deploying web shells and backdoors against education, healthcare, and government targets. #ShinyHunters #OraclePeopleSoft #UNC6240
ShinyHunters resumed mass exploitation of Oracle PeopleSoft CVE-2026-35273, bypassing WAF rules with a percent-encoded path and deploying web shells, Neo-ReGeorg tunnels, and MeshAgent across multiple sectors. #ShinyHunters #OraclePeopleSoft #UNC6240
UNC6240 resumed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft, using a percent-encoded WAF bypass to reach PSEMHUB and deploy web shells across multiple sectors worldwide. #OraclePeopleSoft #ShinyHunters #UNC6240