The extortion group ShinyHunters has restarted mass exploitation of an Oracle PeopleSoft flaw, this time sidestepping the very defenses administrators deployed to stop the first wave.
Mandiant and Google’s Threat Intelligence Group said the group, tracked as UNC6240, modified its exploit for CVE-2026-35273 to bypass web application firewall rules protecting the vulnerable Environment Management Hub endpoint. Once inside, the attackers dropped web shells on dozens of systems worldwide.
PeopleSoft is an enterprise resource planning suite used across healthcare, government, and education to run finance, human resources, payroll, and supply chain tasks. Mandiant said the new campaign spread across higher education, technology, IT services, healthcare, agriculture, transportation, and government.
The original flaw, disclosed in June, was exploited as a zero-day against academic institutions before Oracle patched it on June 10. Organizations that applied workarounds but skipped the patch are the target this time. ShinyHunters also recently claimed credit for an intrusion at the FBI’s jobs site.
Hospitals running PeopleSoft for workforce and finance functions should confirm they are actually patched, not merely shielded by a firewall rule that the group has now learned to evade.