1
ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
ShinyHunters (UNC6240) renewed mass exploitation of Oracle PeopleSoft CVE-2026-35273, bypassing WAFs by URL-encoding a single character in the request path. This campaign expanded global targeting across multiple sectors, deploying web shells and a multi-stage backdoor.
Google Cloud Bloggoogle.com11 minHN5
