Google has issued a warning regarding a renewed mass exploitation campaign targeting Oracle PeopleSoft instances globally. Linked to the ShinyHunters threat group (UNC6240), the attackers are weaponizing CVE-2026-35273, a critical remote code execution vulnerability with a CVSS score of 9.8. The campaign targets various sectors including healthcare, technology, and government by using a URL-encoding technique (/%50SEMHUB/) to bypass web application firewall (WAF) rules.
The attack involves abusing Java deserialization to deploy JSP web shells and the "SIDEEYE" C++ backdoor, facilitating credential theft and unauthorized system access. Security teams are advised to apply patches immediately, disable vulnerable services like EMHub, and monitor for unauthorized access logs or malicious JSP files in application directories to mitigate potential data theft extortion.
Top comments (0)