Google has issued a serious warning regarding a renewed wave of mass exploitation targeting a known security vulnerability in Oracle PeopleSoft. The campaign, which impacts multiple sectors across the globe, is linked to the notorious threat actor group ShinyHunters and centers on the weaponization of a critical flaw tracked as CVE-2026-35273. The security flaw, which carries a maximum severity CVSS score of 9.8, enables unauthenticated remote code execution. This latest development highlights the evolving tactics of cybercriminal organizations and demonstrates how sophisticated threat actors adapt their methodologies to bypass standard defensive controls like web application firewalls. Read Also: SolarWinds Issues Urgent Security Patch for High-Severity Remote Code Execution Flaw in Access Rights Manager Critical Security Flaw in Issabel Framework Under Active Exploitation Following Disclosure The vulnerability first emerged as a zero-day exploit earlier in the year, primarily targeting academic institutions. In those initial attacks, threat actors used the flaw to conduct broad reconnaissance, deploy remote access software such as the MeshCentral agent for persistence, and move laterally across networks using the Secure Shell protocol. Attackers would subsequently execute shell scripts to connect to other internal PeopleSoft machines by leveraging known username and password combinations, ultimately leading to significant data theft. During the initial discovery phase, Google-owned Mandiant reported initiating notifications to more than 100 global organizations whose IP addresses matched vulnerable endpoints, with the majority located in the United States. According to Mandiant, this new wave of activity stems from a threat cluster tracked as UNC6240, which modified its exploit chain specifically to bypass web application firewall rules designed to block requests to the vulnerable Environment Management Hub endpoint, known as PSEMHUB. The threat actors successfully circumvented string-based WAF rules by utilizing URL encoding on a single character within the request path. Instead of requesting the literal path /PSEMHUB/, they submitted requests for /%50SEMHUB/. This simple yet effective trick exploits a common discrepancy in how web architectures handle requests. Many WAFs and reverse proxies inspect and match the literal path before performing URL decoding. However, once the request reaches the PeopleSoft application server, the server decodes the string and correctly routes it to the vulnerable servlet, leaving organizations falsely secure behind their perimeter defenses. The targets of this renewed campaign span a wide array of critical industries, including higher education, technology, IT services, healthcare, agriculture, transportation, and government sectors. Threat actors have successfully deployed web shells on dozens of compromised systems to maintain an operational foothold. Alongside the deployment of specific malicious binaries like Ple64.exe, the threat actors staged the open-source Neo-reGeorg tunneling toolkit to facilitate their operations. To ensure persistent access following the initial placement of web shells on Linux systems, UNC6240 deployed the legitimate Remote Monitoring and Management tool known as MeshAgent. Security telemetry indicates that approximately a quarter of the commands executed by the threat actors were run with elevated privileges—either as root or under the NT AuthoritySYSTEM account—granting the adversaries complete control over the underlying operating systems. The remaining commands were executed under standard PeopleSoft or WebLogic service accounts, providing ample access to internal application logic and stored databases. Google and other security researchers have emphasized that UNC6240 operates with a well-established pattern of data theft extortion. The group routinely steals sensitive corporate and institutional data, threatening to publish the stolen files on dedicated leak sites unless a ransom is paid. Affected organizations have been strongly advised to prepare for potential extortion communications and to monitor closely for any public exposure of proprietary information. This heightened cybersecurity alert coincides with a dramatic escalation involving the ShinyHunters group itself. Recently, the collective claimed responsibility for a high-profile breach of the U.S. Federal Bureau of Investigation’s recruitment portal, FBIJobs.gov, which rendered the application inaccessible. The threat actors allegedly stole between two and three terabytes of sensitive data. According to the group, the motivation behind the FBI portal breach was not financial gain or traditional extortion. Instead, a ShinyHunters spokesperson stated that the hack was executed to contest allegations made by the agency against the group in a security alert published earlier in the year, aiming to set the record straight and protect the organization’s public image. The spokesperson further claimed that the FBI jobs portal was breached using a zero-day vulnerability within Oracle PeopleSoft that is distinct from CVE-2026-35273. Security historians and threat intelligence analysts note that the collective has a long history in the cybercrime underground, having reportedly started as the GnosticPlayers group before rebranding to ShinyHunters. As organizations scramble to patch their Oracle PeopleSoft environments against ongoing exploitation by UNC6240, the intersection of high-profile hacktivism and severe enterprise software vulnerabilities underscores the volatile nature of the current threat landscape. Post navigation Lunex Malware-as-a-Service Platform Unmasked as the Engine Behind Psychedelic Stealer Attacks in Ukraine Unpatched Zero-Day Vulnerabilities in Citrix NetScaler Appliances Actively Exploited in the Wild