CYOPS · Cyber Operations

The PeopleSoft campaign returned in September, and the control that was holding it back was a text match

Mandiant reports a fresh wave of exploitation against CVE-2026-35273, four months after the June zero-day campaign, defeating web application firewall rules by percent-encoding one character in the request path. The same operator now claims a second, unpatched PeopleSoft flaw and an intrusion nobody has confirmed.

The September wave against Oracle PeopleSoft is worth attention for one reason: it did not need a new vulnerability. Mandiant reported on 26 September that operators were exploiting CVE-2026-35273 again, four months after the same flaw was used as a zero-day, and that they were getting past web application firewall rules by percent-encoding the first character of the request path. Firewall and reverse proxy rules matched the literal path before decoding. The PeopleSoft application server decoded it. Web shells followed, on dozens of systems, across higher education, technology, IT services, healthcare, agriculture, transport and government. [1]

The control that was supposed to be holding the line was string comparison against an undecoded URL. That is the finding for anyone running virtual patching as a stopgap: the rule and the application disagreed about what the request said, and the application won.

What the flaw is, and what Oracle said about it

CVE-2026-35273 affects Oracle PeopleSoft Enterprise PeopleTools 8.61 and 8.62, in the Updates Environment Management component. Oracle’s security alert of 10 June 2026 scores it 9.8, network-reachable, no authentication, no user interaction, with high impact to confidentiality, integrity and availability, and directs customers to apply the patch without delay. [2] Rapid7 describes the mechanism as server-side request forgery in the Environment Management Hub and Integration Gateway endpoints, permitting remote code execution and outbound SMB connections that can capture Windows NetNTLM hashes. [3]

Oracle’s alert did not state that the flaw was being exploited. [4] By the time it was published, Mandiant had already placed active exploitation between 27 May and 9 June 2026, with the operator’s data appearing on a leak site on 9 June, a day before the alert. [5] Dustin Childs of the Zero Day Initiative was quoted at the time saying that limited exploitation was being seen and that the investigation was continuing. [4] The advisory and the intrusion set were describing the same week and only one of them said so.

Attribution as the researchers state it

Mandiant and the Google Threat Intelligence Group designate the operator UNC6240 and link it to the group publicly known as ShinyHunters, an assessment they hold with high confidence on the basis of open staging directories containing command history and operational artefacts. [5] SOC Prime characterises the group as financially motivated. [6] R3KONX reports these as the research teams’ assessments and asserts nothing of its own.

The June tooling was commodity rather than bespoke: MeshCentral version 1.1.59 used as command and control, with agent binaries named to resemble Azure operations tooling and a control domain masquerading as a Microsoft Azure file service, plus a shell script performing SSH credential spraying across internal hosts parsed from the local hosts file, and a defacement marker dropped into WebLogic and Process Scheduler directories. [5] The September wave added two JSP web shells, one providing cross-platform command execution and one supporting chunked file upload and execution. [1]

The numbers do not agree, and both belong on the record

Google notified more than 100 organisations, with higher education accounting for 68 per cent of identified targets, predominantly in the United States. [5] The operator’s own claim, reported at the time, was 300 instances across more than 100 organisations. [7] One account records over 40 GB of billing and payment records, card and payment details, student finance data and campus portal exports taken from the campaign, and quotes James Davison, chief security officer at Pathlock, describing the case as an example of the attacks every enterprise resource planning system now faces. [8] The University of Nottingham confirmed a significant data breach. [4] No other victim is named here, because no source read names one.

Arctic Wolf notes that unsupported PeopleTools versions are likely affected as well as 8.61 and 8.62, and describes the intrusion method as chaining older issues with the zero-day. [7] That widens the inventory question beyond the two versions Oracle lists.

The claim that is not established

On 22 September the same operator claimed a second, previously unknown PeopleSoft vulnerability, used to obtain remote code execution on a US federal agency server and move laterally into a government cloud environment, taking between 2 and 3 TB covering current and former employees and job applicants, including criminal justice, human resources and occupational health services. [9][10] No CVE exists for the claimed flaw. The Federal Bureau of Investigation stated only that it is aware of claims regarding unauthorised activity affecting FBIjobs.gov and is investigating. [10][11] BleepingComputer stated it had not independently verified the claimed zero-day, the lateral movement or the volume of data. 404 Media verified some personnel records against public sources. [10][11]

The group also demanded that the bureau retract a May 2026 public service announcement describing its harassment tactics, and said the intrusion was not financially motivated. [12][11] That is an unusual objective for an actor that research teams assess as financially driven, and it is the part of the claim that should attract the most scepticism, not the least. An extortion demand aimed at a document rather than a payment is cheap to make and impossible to audit.

What to do

  • Search WebLogic access logs for requests to the Environment Management Hub path and for percent-encoded variants of it, across the whole period since late May rather than from the patch date. The encoding is the detection string. [1]
  • Inspect the Environment Management Hub web application directory for unexpected JSP files and for unexpected subdirectories, and check environment metadata directories for modified XML. [1][6]
  • Disable or remove the Environment Management Hub service if it is not required, and block external access to it and to the Integration Gateway listening connector at the perimeter. [3][5]
  • Rotate PeopleSoft service account credentials. A web shell on a system that handles human resources and finance data survives the patch, and so does anything it collected. [1]
  • Monitor outbound SMB on TCP 445 from PeopleSoft hosts to external destinations, review database audit logs for unauthorised queries, and look for large archive files staged in temporary directories. [1][3]
  • Extend the version question past 8.61 and 8.62 to unsupported PeopleTools builds still in service. [7]

The cyber operations read

This is the same operator, the same vulnerability and the same product, four months apart, and the only thing that changed was one character of encoding. Nothing in the September wave required capability development. It required the observation that a defensive rule and the software behind it were parsing the same request differently, which is a configuration finding rather than a research finding. Enterprise resource planning platforms concentrate exactly the data that makes an extortion operation viable, and they sit behind controls that are frequently asked to compensate for patches that have not been applied. Where a compensating control is a text match, the compensation is nominal. The claimed second flaw may or may not exist. The demonstrated pattern does not depend on it.

Sources

Every R3KONX article cites its primary material. 12 sources, in order of first citation. Links open the original publication.

  1. Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells The Hacker News · 2026-09-26
  2. Oracle Security Alert Advisory - CVE-2026-35273 Oracle · 2026-06-10
  3. Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273) Rapid7 · 2026-06-10
  4. Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks SecurityWeek · 2026-06-11
  5. ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit Google Cloud (Mandiant / Google Threat Intelligence Group) · 2026-06-11
  6. CVE-2026-35273: Oracle PeopleSoft Zero-Day Exploited in the Wild SOC Prime · 2026-06-15
  7. Critical Oracle PeopleSoft Vulnerability Actively Exploited in ShinyHunters Campaign Arctic Wolf · 2026-06-11
  8. Oracle PeopleSoft zero-day fuels ShinyHunters extortion spree CSO Online · 2026-06-12
  9. ShinyHunters claims FBI breach via new Oracle PeopleSoft zero-day CyberInsider · 2026-09-22
  10. ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach BleepingComputer · 2026-09-22
  11. Hacking group ShinyHunters claims it breached the FBI, stole agents' and applicants' data TechCrunch · 2026-09-22
  12. ShinyHunters claims FBI data theft, demands bureau retract cyber warning Nextgov/FCW · 2026-09-22

Researched and written by the R3KONX analysis desk from the cited primary material. Methodological caveat: attribution and actor designation in this article are reported as the assessments of the named research teams, not as R3KONX findings, and the claims of a second unpatched vulnerability and of an intrusion at a US federal agency are the actor's own, unverified by any vendor or agency at the time of writing. Victim counts from the operator's leak site are claims, published alongside the independently established figures because the two differ. cisa.gov was not reachable from this desk. Corrections to event@r3konx.asia.

R3KONX 2027

Work in this domain? So does the programme

4–6 May 2027, World Trade Centre Kuala Lumpur. Curated talks, hands-on training and The BattleGrid.