Leadership2 publishers3 min readPublished
ShinyHunters breaks into PeopleSoft systems that chose firewall rules over Oracle's patch
Mandiant says ShinyHunters has planted web shells on dozens of Oracle PeopleSoft systems by URL-encoding one character to get past firewall rules. Employers that treated June's stopgap as the fix now have to patch and also look for any access the attackers left behind.
The Board Room · Leadership desk

What happened
- ShinyHunters first exploited the PeopleSoft flaw, CVE-2026-35273, as a zero-day between May 27 and June 9, 2026.
- Oracle released an out-of-band security alert on June 10, 2026, the day after that zero-day window closed.
- According to HRD, most victims of the new wave had answered the first attacks with a temporary workaround instead of installing Oracle's fix.
- After the first wave, Nissan told employees in the US, Canada, Mexico and Brazil that their Social Security numbers and bank details may have been stolen.
- ShinyHunters also claimed it took payroll and medical records from the Council of Europe.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- exposure Systems that ran only the workaround need a compromise check as well as the patch, and a check that looks only for new JSP files would miss the fileless method Mandiant observed.
- precedent Attackers can now be expected to study and test any interim control described in a public advisory, so a filter buys less time than a patch schedule may assume.
- decision A status of 'mitigated' on a risk register now has to say whether it means patched or filtered, and HRD advises HR to get IT's answer in writing and ask payroll vendors running PeopleSoft the same.
- cost Employees bear the loss when stolen bank details are used to redirect wages, and HR ends up adding controls such as Nissan's rule that deposit details change only from company networks.
The bypass works because two systems read the same request in a different order. Many firewall and reverse proxy rules compare the literal path before decoding it, while the PeopleSoft application server decodes the path first and then routes the request [5]. A rule written to block /PSEMHUB/ does not match /%50SEMHUB/, where %50 is the encoded letter P, and the server still passes the request to the vulnerable servlet [5]. Mandiant now advises enforcing the block on the normalized path and assuming attackers will try any percent-encoded or mixed-case variant [19].
The board-deck version of the June response would have been one word: mitigated. Mandiant wrote that the bypass reaches systems "whose operators may have believed their WAF rules had mitigated the exposure" [20]. On the new wave, Mandiant said workarounds "are not a substitute for patching" [8].
The trade-off in June was speed against coverage. Mandiant's June guidance put patching first. It offered the perimeter block only where patching or disabling EMHub was not immediately possible, and it warned that WAF body-inspection rules alone were insufficient [4]. An operations lead could fairly say the filter was what the guidance allowed. It was, as a fallback [4]. In Mandiant's account, the group then adapted to that published guidance and went after organizations that had the WAF rules but not the patch [6].
Patching is this quarter's decision. Whether the attackers are already inside decides next quarter's, and in my view the two jobs need separate owners. Before exploiting a server, the group typically sent it five to 15 probe requests, and unpatched servers answered with their operating system without writing any files [9]. Mandiant says hosts that were confirmed but not yet exploited may show those probes in logs with nothing after them [9]. Where the group did go in, it deployed two web shells for persistent access and follow-on payloads [12]. It also sent bursts of requests, which Mandiant says likely put a copy on each node behind a load balancer, and it advises checking every WebLogic node, not only the first one found [10].
Mandiant and HRD did not identify the organizations hit in the new wave, and neither account shows they are the employers breached in June. The first wave was mostly higher education [2]. The new one also reaches technology, IT services, healthcare, agriculture, transportation and government [1]. The second wave found organizations that stopped at the workaround, whether or not they had been hit before [6][7].
Being on this group's list costs more than the data. The FBI warned in May that the group sometimes harasses victims and their relatives with threatening calls and texts, and in some cases has used swatting [18]. Days before Mandiant's warning, ShinyHunters said it had hacked the FBI's recruitment website and taken data on agents and job applicants. The bureau said it was "actively and aggressively investigating" [17].
What to watch
- Whether Mandiant or affected employers name second-wave victims or confirm what data left the compromised PeopleSoft servers.
- Breach notices to current staff, former staff and applicants from organizations that ran only the workaround, as Nissan sent after June.
- Ransom demands or harassment directed at second-wave victims, of the kind the FBI warned about in May.