ShinyHunters walked around the firewall rules that many PeopleSoft operators put up after June’s zero-day, according to Mandiant and Google Threat Intelligence Group (GTIG). A blocked path buys time, and only the vendor’s patch removes the flaw.
What Mandiant reported
On September 25, Mandiant and GTIG published an update on CVE-2026-35273, a flaw in Oracle PeopleSoft PeopleTools. Oracle describes it as remotely exploitable without authentication and capable of resulting in remote code execution. Oracle’s alert covers PeopleTools versions 8.61 and 8.62 and was first released on June 10, 2026.
The new report says the group Mandiant tracks as UNC6240, and identifies as ShinyHunters, is running a renewed mass-exploitation campaign against the same bug. In June, Mandiant reported that the actor used the flaw as a zero-day between May 27 and June 9, mostly against higher education institutions. This time the targets are broader. Mandiant says the actor deployed web shells on dozens of systems worldwide, across higher education, technology, IT services, healthcare, agriculture, transportation and government.
How the workaround failed
The interesting part is the route in. Mandiant’s June guidance told operators to patch and, where they could not, to block external access to the vulnerable Environment Management Hub path at the perimeter. Many organizations did something close to that with a web application firewall rule.
According to Mandiant, UNC6240 changed its requests so that the path arrived in a percent-encoded form. Many firewall and reverse proxy rules match the literal path before decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet anyway. Operators who believed a rule had mitigated the exposure were still reachable. Mandiant says the actor adapted to its published guidance and is hitting organizations that added WAF rules but never patched. Its advice is plain: WAF rules and path-based blocking are not a substitute for patching.
The same report advises defenders to enforce blocking on the normalized path rather than the raw string, since the actor may try any encoded, mixed-case or otherwise non-normalized variant.
What the attackers did once inside
Mandiant describes a consistent sequence. Before exploiting a server, the actor sent five to 15 requests that let it confirm the host was vulnerable without writing files or disrupting the service. Hosts that were validated but not yet exploited may show only those requests in their logs, with no follow-on activity.
Two ways in, two detection problems
Mandiant observed two exploitation methods. In the first, the actor placed web shells in the application’s directory, sending a burst of requests so that every node behind a load balancer received a copy. In the second, commands ran and returned output in the HTTP response with no file written to disk. Detections that watch for new script files will miss the second method. Mandiant says the fileless variant shows up on the host as shell processes spawned by the WebLogic Java process.
Persistence and tooling
After the web shells, Mandiant reports a backdoor it calls SIDEEYE, delivered inside a trojanized installer signed with a valid Extended Validation certificate. GTIG says it has asked the certificate authority, Sectigo, to revoke that certificate. The actor also staged an open-source tunneling toolkit that routes traffic through ordinary web connections, and on Linux systems deployed MeshAgent, a legitimate remote management tool, for persistent access.
Mandiant also found that about a quarter of the actor’s commands ran as root or SYSTEM. The rest ran under PeopleSoft or WebLogic service accounts, which still expose configuration files, database connection strings and application data. Mandiant notes that UNC6240 has a well-established pattern of stealing data and threatening to publish it unless the victim pays, and tells affected organizations to prepare for extortion contact.
What it means for the security leader
Stopgaps that get treated as fixes are a recurring theme in our coverage. CyberTech reported that Citrix patched its NetScaler bugs weeks after attackers used them, and that CISA’s patch deadlines are outrunning adoption. We also argued that a patch existing is not the same as a patch applied. The PeopleSoft campaign fits the same shape: the fix has been public since June 10, and the exploited population is the set of organizations that reached for a compensating control instead.
The business cost is specific. PeopleSoft commonly sits in front of HR, payroll and student records. Mandiant tells defenders to review database audit logs for bulk queries or exports against those tables. A security leader who accepted “WAF rule in place” as the closing note on a June ticket should reopen it, because that status no longer means what the ticket implied.
It also changes how to read compensating controls in a risk register. A control that inspects strings is only as good as its normalization. Any exception that rests on a filter rather than a fix needs an owner, an expiry date and a test that tries a variant of the blocked request, run by your own team.
What to do this week
- Confirm the Oracle Security Alert patch for CVE-2026-35273 is applied on every PeopleSoft environment, including test and disaster recovery copies. Mandiant says WAF rules are not a substitute.
- Disable the Environment Management Hub service where it is not needed, or remove the application in single-server setups, as Oracle’s guidance advises.
- Search WebLogic access logs for requests to the hub path and its encoded variants, and check every node behind a load balancer, not only the first one that alerts.
- Look for unexpected script and executable files in the application directory, and for shell processes spawned by the WebLogic Java process.
- If you find a web shell, treat the host as compromised, preserve evidence and rotate every credential reachable from the PeopleSoft tier, starting with hosts where the service runs as root or SYSTEM.
- Brief legal and communications teams now. Mandiant expects extortion attempts.
Indicators of compromise are listed in Mandiant’s post and in a Google Threat Intelligence collection for registered users.
Source: Google Cloud Threat Intelligence (Mandiant and GTIG)

