ShinyHunters hackers are going after Oracle systems once again - here's what we know
Mitigations are no longer mitigating, and patching is now the only method of defense.
ShinyHunters, notorious data extortionists, are once again targeting Oracle's PeopleSoft systems. In June 2026, they exploited a critical zero-day vulnerability in the PeopleSoft Environment Management Hub (PSEMHUB) servlet, allowing them to execute arbitrary code and deploy web shells. Oracle released a patch for CVE-2026-35273 on June 10, 2026, and added the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog on June 12.
ShinyHunters have now discovered a way to bypass mitigation measures implemented in response to the initial exploit. By URL-encoding a single character in the request path, they can bypass web application firewall (WAF) rules that previously blocked the vulnerable PSEMHUB endpoint. This new attack vector is now being used against organizations globally, not just higher education institutions, targeting a wide range of sectors, including technology, healthcare, government, and agriculture.
Mandiant and Google's Threat Intelligence Group (GTIG) recommend several steps for organizations affected by this threat. First and foremost, they should apply Oracle's patch for CVE-2026-35273, which addresses the underlying vulnerability. Additionally, organizations should disable the Environment Management Hub (EMHub) service in multi-server configurations or remove the PSEMHUB application entirely in single-server configurations.
They should also search their PeopleSoft access logs for requests to /PSEMHUB) and its percent-encoded variants, as well as inspect the /webserv/ /applications/peoplesoft/PSEMHUB.war/ directory for any stray or unauthorized files. Finally, credentials associated with the PeopleSoft application service account should be rotated, and outbound traffic from PeopleSoft hosts should be monitored for any suspicious activity.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.