proomt

Search

Search posts, papers, and topics

All posts

Google Cloud BlogMandiant11 min readadvanced

ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

Summary

ShinyHunters (UNC6240) renewed mass exploitation of Oracle PeopleSoft CVE-2026-35273, bypassing WAFs by URL-encoding a single character in the request path. This campaign expanded global targeting across multiple sectors, deploying web shells and a multi-stage backdoor.

  • Threat actors bypassed WAFs blocking /PSEMHUB/ by URL-encoding 'P' to /%50SEMHUB/, as WAFs often match literal paths before decoding.
  • Patching CVE-2026-35273 is critical; WAF rules are not a substitute and can be bypassed by simple encoding.
  • Exploitation abuses Java deserialization in PSEMHUB, leading to web shell deployment (x.jsp, u.jsp) or fileless command execution.
  • x.jsp provides cross-platform command execution using hex-encoded commands and OS detection to evade WAFs.

Organizations using Oracle PeopleSoft must immediately patch and review their WAF configurations, as an active, sophisticated threat actor is exploiting a known vulnerability with WAF bypass techniques.

8/10

Related reading

  1. Transform and route security logs to Microsoft Sentinel tables using Observability Pipelines

    Datadog Observability Pipelines now ships pre‑built Microsoft Sentinel Packs that map logs from Palo Alto, Fortinet, Cisco ASA, Cisco Meraki, and ExtraHop into Sentinel’s CommonSecurityLog or Syslog tables. Packs handle field extraction, severity derivation, and device‑action mapping, letting you filter or drop low‑value events before ingest, validate mappings with Live Capture, and reduce per‑GB…

    Datadogdatadoghq.com5 min
  2. How we tracked down a 16-year-old SQLite bug

    Tailscale experienced 19 SQLite database corruptions over six months due to a 16‑year‑old bug in SQLite’s WAL checkpoint logic. The single‑writer, Go‑driven shard architecture forced them to add forensic telemetry, a transaction‑logging replay pipeline, and work directly with SQLite core developers to isolate and fix the issue, dramatically reducing downtime.

    Tailscaletailscale.com14 minpostmortemHN1223239
  3. September 16, 2026 security incident: how we responded to a LiteSpeed zero-day attack

    Hostinger detected a zero‑day exploit in LiteSpeed Web Server on a Brazil server on Sep 16 2026, giving the attacker root access and compromising 399 accounts. The team isolated the server, coordinated with LiteSpeed to patch the vulnerability, rolled out the fix fleet‑wide, and restored affected sites from backups within the same day.

    Hostingerhostinger.com2 minpostmortem