ShinyHunters found a crack in Oracle's patch job for PeopleSoft - and they're exploiting it globally.
In June 2026, Oracle patched a critical Java deserialization bug in PeopleSoft's Environment Management Hub, CVE-2026-35273, rated 9.8 out of 10. For organizations that couldn't apply the fix right away, Oracle offered a stopgap: web application firewall rules blocking the vulnerable /PSEMHUB/ endpoint. Google's Threat Intelligence Group and Mandiant now say the group behind the original attacks, tracked as UNC6240, simply URL-encoded one character in the request path - swapping /PSEMHUB/ for /%50SEMHUB/ - to slip past those WAF rules undetected. The trick works because many firewalls check the literal path before decoding, while PeopleSoft's own server decodes it anyway and routes the request straight to the vulnerable servlet.
This isn't a new vulnerability - it's proof that a workaround isn't a fix. Unpatched systems that thought they were covered by WAF rules are exposed again, and this time the target list has grown from mostly universities to technology, healthcare, government, agriculture, and transportation companies. ShinyHunters aren't just breaking in for fun; they use the access to steal HR and payroll data and run extortion campaigns.
Oracle's actual patch, issued back in June, still closes the hole - so the fix here isn't clever detection, it's just applying the update everyone was supposed to install three months ago.