Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
AI Summary
Threat actor UNC6240, linked to ShinyHunters, is exploiting CVE-2026-35273, a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft, to deploy web shells and establish persistent access. The attackers bypass web application firewall (WAF) protections by URL-encoding the 'P' character as '%50' in requests to the vulnerable PSEMHUB endpoint. Exploitation leads to fileless command execution, deployment of JSP web shells, and installation of the SIDEEYE backdoor and Neo-reGeorg tunneling toolkit for data exfiltration and lateral movement. Targets span multiple sectors including education, healthcare, government, and technology, with the threat actor demonstrating root- and SYSTEM-level access on compromised systems.
AI-extracted · verify before operational use