The Patch Isn’t the Perimeter: ShinyHunters Just Beat the WAF Rule You Were Counting On

Executive threat briefing, Monday, September 28, 2026

One character. That’s all it took to reopen PeopleSoft.

In June, ShinyHunters broke into more than 100 organizations through an Oracle PeopleSoft zero-day. Defenders wrote WAF rules to stop it. Now the group is back, encoding the letter “P” as %50 and walking straight past those rules, into higher education, healthcare, government and more.

Executive summary

The fix you deployed in June may not be a fix anymore.

On September 25, Google’s Mandiant and Threat Intelligence Group (GTIG) reported that UNC6240, the extortion crew known as ShinyHunters, has resumed mass exploitation of Oracle PeopleSoft through CVE-2026-35273, a 9.8-rated unauthenticated remote code execution flaw.

The twist: the attackers aren’t beating the patch. They’re beating the organizations that never applied it and relied on web application firewall rules instead. By requesting /%50SEMHUB/ rather than /PSEMHUB/, their traffic slips past string-matching rules, while PeopleSoft’s application server decodes the path and serves the vulnerable endpoint anyway.

Mandiant has found web shells on dozens of systems worldwide, a new backdoor called SIDEEYE, and a target list that now spans higher education, technology, IT services, healthcare, agriculture, transportation and government.

If PeopleSoft runs your payroll, HR or student records and you mitigated instead of patched, treat this as an active incident until you prove otherwise.

Why this matters to CISOs and security leaders

PeopleSoft isn’t a peripheral app. It holds payroll, Social Security numbers, bank details, HR files, financial ledgers and student records. For a data-extortion crew, it’s the most valuable single system in the building.

This campaign also exposes a quiet failure in how many enterprises run vulnerability management. When a critical patch is hard to schedule, teams reach for a compensating control, mark the risk as mitigated, and move on. ShinyHunters read the same public guidance defenders did, and built its comeback around the gap.

Mandiant says as much: the group adapted to published defensive guidance and went after organizations that deployed WAF rules but didn’t patch.

Executive insight

Ask your team one question today: “Which of our ‘mitigated’ criticals are mitigated by a rule rather than removed by a patch?” That list is your real exposure. Every entry on it is a bet that attackers won’t find a way around the rule. On PeopleSoft, that bet just lost.

How we got here: from zero-day to relapse

DateWhat happened
May 27 – June 9, 2026ShinyHunters exploits CVE-2026-35273 as a zero-day, mostly against universities. No patch exists.
June 10Oracle issues an out-of-band Security Alert and fix.
June 11–12Mandiant publishes its first report. CISA adds the flaw to the Known Exploited Vulnerabilities catalog. Guidance: patch, or block /PSEMHUB/* at the perimeter if you can’t yet.
June – AugustThe group claims more than 300 compromised PeopleSoft instances across over 100 organizations. Intrusions continue into July using MeshAgent remote access.
September 2026Renewed mass exploitation using the %50SEMHUB WAF bypass. Targeting expands across sectors and regions.
September 25Mandiant and GTIG publish the follow-up report with new tooling, IOCs and remediation guidance.

How the WAF bypass actually works

The vulnerable component is the Environment Management Hub (PSEMHUB), an administrative servlet that should never have been reachable from the internet in the first place.

Many WAF and reverse-proxy rules check the raw request path for the literal string /PSEMHUB. But %50 is simply the URL-encoded form of the letter P. The WAF sees /%50SEMHUB/, finds no match, and waves it through. WebLogic then decodes the path back to /PSEMHUB/ and hands the request to the vulnerable servlet.

The WAF and the application disagreed about what the URL said. The attacker lived in that disagreement.

What nobody is talking about: this is a normalization bug, not a PeopleSoft bug. Any rule that matches a path before decoding is vulnerable to the same trick, on any application. Mandiant’s advice applies broadly: assume attackers will try every percent-encoded, mixed-case or non-normalized variant, and enforce blocking on the normalized path.

Inside the attack chain

1. Quiet verification

Before exploiting anything, the attackers send five to 15 POST requests containing a serialized Java object to /%50SEMHUB/hub. An unpatched server answers with its operating system, without writing files or disrupting service. It’s a silent “you’re vulnerable” check.

The hidden enterprise risk: if you see these probes in your logs with nothing after them, you haven’t dodged the attack. You’ve been shortlisted.

2. Two ways in

Mandiant observed two exploitation methods, both abusing Java deserialization in the hub servlet:

  • Web shell deployment. A burst of requests drops JSP files such as x.jsp into the PSEMHUB directory. The burst likely ensures every node behind a load balancer gets a copy, so checking only one WebLogic node isn’t enough.
  • Fileless execution. Commands run directly and return output in the HTTP response, with nothing written to disk. On the host, it looks like the WebLogic Java process spawning cmd.exe or /bin/sh. Detections built on file creation will miss it entirely.

3. Built to dodge detection

The two web shells are single-line JSP files designed to stay quiet. x.jsp takes hex-encoded commands over POST instead of readable query strings, and even assembles the /bin/sh path from character codes to avoid static signatures. u.jsp uploads large files in 150 KB Base64 chunks to get around request-size limits.

4. A new backdoor: SIDEEYE

On Windows servers, the group uploaded a 5.2 MB file called Ple64.exe, disguised as a signed installer for the Light Alloy media player. It’s a trojanized installer carrying a three-stage chain that ends by loading a C++ backdoor, SIDEEYE, entirely in memory. The middle stage is protected with VMProtect.

The sample was signed with a valid Extended Validation code-signing certificate, which GTIG has asked the issuer to revoke. SIDEEYE can steal browser and desktop credentials, manage files and processes, and open reverse shells and proxies.

5. Tunnels and remote control

The attackers also deployed Neo-reGeorg, an open-source toolkit that tunnels SOCKS5 traffic through ordinary web requests, turning the PeopleSoft server into a doorway into the internal network. On Linux hosts they installed MeshAgent, a legitimate remote-management tool, and pointed it at infrastructure dressed up to look like IT or Microsoft services.

Why CISOs are worried

According to Mandiant, a quarter of the attackers’ commands ran as root or SYSTEM, meaning full control of the operating system. The rest ran under PeopleSoft or WebLogic service accounts, which still unlock configuration files, database connection strings and application data. Either way, the attacker can reach the crown jewels.

Who is being targeted

June’s wave hit universities hardest. September’s doesn’t discriminate. Mandiant has confirmed compromises across:

SectorData at risk in PeopleSoft
Higher educationStudent records, financial aid, staff payroll
HealthcareEmployee HR and payroll, benefits data
GovernmentPublic employee records, financials
Technology and IT servicesHR data, and potential downstream access to clients
Agriculture and transportationPayroll, finance, supplier and vendor data

Competitive pressure: IT services firms deserve special attention. A compromised provider’s PeopleSoft tier can hold credentials and data that reach beyond its own walls, which turns one intrusion into a supply-chain problem for every client.

No encryption. No mercy. Just extortion.

ShinyHunters doesn’t need ransomware. The group steals data, threatens to post it on a leak site and demands payment. Mandiant warns affected organizations to prepare for extortion contact and to watch for public exposure of stolen records.

That changes the incident calculus. Backups don’t help when nothing is encrypted. Business-interruption cover matters less. Breach notification, regulatory exposure under state privacy laws and education and health data rules, and litigation risk matter far more. If you carry cyber insurance, notify your carrier early. Most policies have strict reporting windows.

Winners and losers

In good shapeExposed right now
Teams that applied Oracle’s June fixTeams that deployed a WAF rule and deferred the patch
Deployments with EMHub disabled or removedPSEMHUB reachable from the internet
WAFs that block on the decoded, normalized pathRules that match raw strings before decoding
EDR watching what the WebLogic process spawnsDetection that only looks for dropped files
Organizations on supported PeopleTools versionsUnsupported releases with no fix available

What security leaders should do next

In the next 24 hours

  1. Patch. Apply Oracle’s Security Alert fix for CVE-2026-35273 on every PeopleSoft environment, including test and dev. Mandiant is explicit: WAF rules and path blocking are not a substitute.
  2. Shrink the target. Disable the EMHub service in multi-server setups, or remove the PSEMHUB application in single-server setups, per Oracle’s guidance. Block EMHub and the Integration Broker listening connector from the internet. Mandiant notes this doesn’t break normal user sessions.
  3. Fix the rule. Until patching is done, make sure your WAF normalizes and decodes paths before matching, and blocks every encoded and mixed-case variant of /PSEMHUB/.

This week: hunt

  1. Search WebLogic access logs for /PSEMHUB/ and any encoded variant such as /%50SEMHUB/, especially external POST requests to /hub and requests for .jsp files.
  2. Inspect every node for files that don’t belong in PSEMHUB.war/ or PORTAL.war/, including x.jsp, u.jsp, tunnel.jsp, tunnel.jspx and Ple64.exe.
  3. Alert on process behavior: shells spawned by the WebLogic Java process, especially running base64 -d, curl, /dev/tcp, tasklist or start /b. Look for unexpected MeshCentral agents.
  4. Look for data theft: large .tar, .tar.gz or .zst archives in temp or web directories; tar, zstd, rsync, sshpass or curl run by PeopleSoft service accounts; bulk queries against HR, payroll and student tables; and large outbound transfers, including rsync on TCP 873.

If you find anything

  1. Treat the host as compromised. Preserve evidence before cleanup.
  2. Rotate every credential the PeopleSoft tier can read: database connection strings in psappsrv.cfg, Integration Broker credentials and any cloud credentials reachable from the web tier. Start with hosts where WebLogic runs as root or SYSTEM.
  3. Brief legal, communications and your insurer now, and prepare for an extortion demand.

Indicators of compromise

From Mandiant and GTIG’s September 25 report. Web shell hashes vary between samples, so hunt on file names and paths as well as hashes.

IndicatorTypeRole
5.199.162.157IPv4Attack controller, scanner and callback receiver
104.219.234.138IPv4Exfiltration staging and remote management
162.219.30.165IPv4SIDEEYE command and control (TCP 3333 and 3334)
winmanage-me.networkDomainMeshCentral staging infrastructure
azurenetfiles.net, microsoft-entra.net, enroll.azuredevice.cloudDomainsMicrosoft-lookalike MeshAgent infrastructure (May and July intrusions)
/%50SEMHUB/URIEncoded WAF bypass path
Ple64.exe
3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3
SHA-256Trojanized installer delivering SIDEEYE

The full IOC set, including web shell hashes and MITRE ATT&CK mapping, is in Mandiant’s report.

Forward this to whoever owns PeopleSoft

The hunt steps above take hours, not weeks. The team that runs PeopleSoft and the team that runs your SOC need to see this briefing today, together.

What happens next

More victims will surface. Web shells are on dozens of systems, and ShinyHunters’ model depends on publicizing stolen data to force payment. Expect leak-site postings and breach notifications over the coming weeks.

Other groups will copy the trick. The bypass is now public and trivially simple. Once a technique is this easy, it rarely stays with one actor.

The lesson will outlive PeopleSoft. Any critical flaw “mitigated” by a string-matching rule is exposed to the same idea. Security leaders should expect boards and regulators to start asking not just “did you mitigate?” but “did you patch?”

Final executive takeaway

ShinyHunters didn’t find a new vulnerability. They found the organizations that treated a firewall rule as a finish line.

Patch PeopleSoft. Take EMHub off the internet. Hunt every node. Rotate the credentials. And then go find every other “mitigated” critical in your environment, because the next %50 is already out there.

Frequently asked questions

What is CVE-2026-35273?

CVE-2026-35273 is a critical (CVSS 9.8) unauthenticated remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools, in the Updates Environment Management component behind the Environment Management Hub (PSEMHUB). It requires no login and no user interaction.

Who is ShinyHunters?

ShinyHunters, tracked by Mandiant as UNC6240, is a financially motivated cybercrime group known for data theft and extortion. It steals data and threatens to publish it on a leak site unless the victim pays.

How does the ShinyHunters WAF bypass work?

The attackers request /%50SEMHUB/ instead of /PSEMHUB/. %50 is the URL-encoded letter P. WAF rules that match the literal path before decoding miss it, while the WebLogic server decodes the path and routes the request to the vulnerable servlet.

Is a WAF rule enough to protect PeopleSoft?

No. Mandiant states that WAF rules and path-based blocking are not a substitute for patching. Apply Oracle’s Security Alert fix, and disable or remove EMHub where it isn’t needed.

What is SIDEEYE?

SIDEEYE is a C++ backdoor delivered by a trojanized installer named Ple64.exe that poses as a Light Alloy media player installer. It runs in memory and can steal credentials, manage files and processes, and provide reverse shell and proxy access.

Which sectors are being targeted?

Mandiant has observed web shells on systems in higher education, technology, IT services, healthcare, agriculture, transportation and government, across multiple countries.

How do I know if my PeopleSoft servers were compromised?

Search WebLogic logs for /PSEMHUB/ and encoded variants, check every node for unexpected .jsp, .jspx and .exe files in PSEMHUB.war and PORTAL.war, look for shell processes spawned by the WebLogic Java process, and review outbound traffic for the published indicators and large data transfers.

Sources

Mandiant and Google Threat Intelligence Group, “ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft” (Sept. 25, 2026); Oracle Security Alert for CVE-2026-35273; CISA Known Exploited Vulnerabilities catalog; BleepingComputer; The Hacker News; Rapid7; Arctic Wolf. Details current as of September 28, 2026. Victim counts claimed by ShinyHunters have not been independently verified.

Similar Posts