Google has issued a stark warning to global organizations following a resurgence in the mass exploitation of a critical security vulnerability within Oracle PeopleSoft environments. The threat, identified as CVE-2026-35273, carries a maximum CVSS score of 9.8, indicating a high level of severity that allows unauthenticated remote code execution. The campaign is currently attributed to the threat actor group known as UNC6240, which is operationally linked to the notorious ShinyHunters collective. This sophisticated intrusion campaign spans multiple high-value sectors, including technology, government, healthcare, and higher education, raising significant concerns about the persistence and adaptability of modern cyber-extortion operations.
Chronology of the Exploitation Campaign
The lifecycle of CVE-2026-35273 began earlier this year when it was first observed being weaponized as a zero-day exploit. Initial targets were predominantly academic institutions, where the vulnerability served as a gateway for reconnaissance and the establishment of long-term persistence. During this early phase, attackers deployed remote access tools, specifically the MeshCentral agent, to maintain a foothold. Once inside, the threat actors utilized SSH-based lateral movement, leveraging known credential combinations to compromise internal PeopleSoft infrastructure and harvest sensitive organizational data.
By mid-2026, the activity escalated. Mandiant, a subsidiary of Google, reported that it had initiated notifications to over 100 global organizations—primarily based in the United States—whose internet-facing endpoints showed clear signs of compromise. Despite these warnings and subsequent patching efforts by some organizations, the threat actors have demonstrated a high degree of technical agility, refining their methods to bypass existing security controls.

The most recent wave of attacks, identified by security researchers, indicates that UNC6240 has successfully modified its exploit delivery mechanism to circumvent Web Application Firewall (WAF) rules. Many organizations had previously implemented string-based WAF rules to block requests directed at the vulnerable Environment Management Hub (PSEMHUB) endpoint. The attackers successfully bypassed these defenses by utilizing URL encoding. By requesting "/%50SEMHUB/" instead of the standard "/PSEMHUB/", the threat actors exploited a discrepancy between how WAFs and backend servers process URL-encoded characters. While the WAF typically matches the literal path before decoding, the PeopleSoft application server decodes the request, allowing the malicious traffic to reach the vulnerable servlet unabated.
Technical Breakdown and Attack Methodology
The sophistication of the UNC6240 campaign is further evidenced by the diverse toolkit employed once initial access is achieved. Upon bypassing the WAF, the attackers move to establish a more permanent presence. This involves the deployment of web shells on dozens of systems across the targeted networks.
Beyond simple access, the attackers stage the open-source Neo-reGeorg tunneling toolkit, a powerful utility that facilitates persistent, obfuscated communication between the attacker’s infrastructure and the compromised server. For Linux-based environments, the group has been observed deploying MeshAgent, a legitimate Remote Monitoring and Management (RMM) tool, which provides the attackers with a convenient, "living-off-the-land" mechanism for persistent access that often evades detection by traditional antivirus solutions.
Data provided by Google’s security researchers highlights the extent of the administrative control seized by the attackers. Approximately 25% of the commands issued by UNC6240 are executed with elevated privileges, specifically as root or NT AUTHORITYSYSTEM. This level of access grants the attackers near-total control over the underlying operating systems. The remaining activities are conducted under the context of PeopleSoft or WebLogic service accounts, which are sufficient to access, modify, and exfiltrate the sensitive business and personal data managed by these enterprise resource planning systems.

Broader Context: The ShinyHunters Connection
The involvement of the group linked to ShinyHunters adds a layer of geopolitical and reputational complexity to these technical breaches. ShinyHunters, which security researchers note emerged from the remnants of the GnosticPlayers collective, has recently been involved in a high-profile dispute with the U.S. Federal Bureau of Investigation (FBI).
In September 2026, the group claimed responsibility for breaching the FBIJobs.gov portal, asserting they exfiltrated approximately 2 to 3 terabytes of sensitive data. In statements provided to various media outlets, the group’s spokesperson characterized the breach as a retaliatory act designed to "set the record straight" regarding allegations made by the FBI in a May 2026 security alert. The group explicitly denied that the FBI breach was financially motivated, differentiating it from the extortion-based tactics they employ against private sector organizations.
However, the juxtaposition of the FBI breach and the ongoing Oracle PeopleSoft campaign highlights the dual nature of these actors. While they may engage in ideological "hacktivism" against state entities, their bread-and-butter operations involve the systematic theft of proprietary data from corporations, followed by standard extortion demands. Google has advised that all organizations currently targeted by UNC6240 should prepare for extortion communications, as the group maintains a well-established pattern of threatening to leak stolen data on public platforms unless a ransom is paid.
Implications for Enterprise Security
The mass exploitation of CVE-2026-35273 underscores a critical vulnerability in the modern security perimeter: the reliance on static WAF rules to protect complex enterprise applications. When security appliances and backend applications interpret web requests differently—as seen in the URL encoding bypass—defenses that seem robust on paper can be rendered useless in practice.

The implications for organizations are significant. Beyond the immediate risk of data theft and potential regulatory fines associated with data breaches, the deployment of web shells and RMM tools indicates that victims are likely to remain compromised for extended periods if a thorough incident response and remediation process is not undertaken.
Recommended Mitigation Strategies
To counter the threat posed by UNC6240, security teams are urged to move beyond simple string-matching rules in their WAF configurations. Organizations should prioritize the following measures:
- Immediate Patching: Ensure that all Oracle PeopleSoft installations are updated to the latest versions released by Oracle to address CVE-2026-35273.
- Advanced WAF Configuration: Update WAF policies to ensure that input normalization is performed before rule evaluation. This prevents attackers from hiding malicious characters behind URL encoding.
- Endpoint Monitoring: Implement rigorous monitoring for unauthorized RMM tools, such as MeshAgent, and suspicious web shell activity. Baseline the behavior of service accounts associated with PeopleSoft and WebLogic to detect anomalies.
- Credential Rotation: In the event of a breach, treat all internal credentials as compromised. Perform a full rotation of service account passwords and SSH keys used for lateral movement.
- Extortion Preparedness: Develop and test an incident response plan specifically tailored to data extortion. This should include communication strategies, legal consultation, and the monitoring of dark web forums for the appearance of stolen corporate assets.
As the digital landscape continues to evolve, the ability of threat actors like UNC6240 to pivot from exploiting software flaws to conducting sophisticated, multi-stage extortion campaigns represents a major challenge for cybersecurity professionals. The current situation with Oracle PeopleSoft serves as a potent reminder that even highly mature organizations remain vulnerable to well-resourced actors who are capable of identifying and exploiting the nuances of web traffic processing. The resilience of an organization now depends not only on the software it deploys but on the vigilance of its security operations in identifying the subtle signs of a persistent and determined adversary.
