PeopleSoft attackers are walking past WAF rules. Patch HR and payroll servers now

By George Bailey   Published: 09/29/26   6 min read

In June, a lot of PeopleSoft teams bought time the sensible way: a web application firewall rule that blocked the vulnerable Environment Management Hub path while the real patch waited for a change window. Google now says ShinyHunters has a way past that rule, and it is almost insultingly small. The attackers encode the first letter of the path. The WAF sees a string it does not recognize. PeopleSoft decodes it and runs the request anyway.

If your HR, payroll, finance, or student records live on PeopleSoft and the June fix is not actually installed, this is the week to close it for real.

A WAF rule that matches the text of a path is not a patch. It is a spelling test, and attackers can spell.

What happened

Mandiant and Google Threat Intelligence Group (GTIG) reported over the weekend a renewed mass-exploitation wave against CVE-2026-35273, the unauthenticated remote code execution flaw in PeopleSoft Enterprise PeopleTools (Updates Environment Management, versions 8.61 and 8.62) that Oracle fixed in an out-of-band Security Alert on June 10, 2026. Google tracks the actor as UNC6240, the group better known as ShinyHunters. It exploited the same bug as a zero-day in late May and early June, mostly against universities.

Back then, the advice for teams that could not patch immediately was to block external access to /PSEMHUB/*. According to Google, the group now sends its requests to /%50SEMHUB/hub instead. %50 is the URL-encoded letter P. Many WAFs and reverse proxies compare the literal path before decoding it, so the rule never fires, while WebLogic decodes the request and routes it to the vulnerable servlet.

The new wave has placed web shells on dozens of systems in higher education, technology, IT services, healthcare, agriculture, transportation, and government. Google describes a quiet sequence: five to 15 POST requests carrying serialized Java objects that return host details without writing files, then exploitation that runs commands in memory or drops small JSP web shells (x.jsp, u.jsp, u2.jsp) in the PSEMHUB application directory. On Windows servers the attackers loaded a backdoor Google calls SIDEEYE through a trojanized installer named Ple64.exe. They also staged the Neo-reGeorg tunneling kit and used the legitimate MeshAgent remote management tool on Linux hosts. About a quarter of the commands ran as root or SYSTEM.

The timing overlaps with the FBI story. Over the weekend the FBI reportedly told employees in an internal notice that names, addresses, job titles, and Social Security numbers were exposed in the hack of its FBIJobs.gov portal. ShinyHunters says it got in through PeopleSoft and claims a separate, new flaw in the same PSEMHUB component. That claim is not verified. The group did tell BleepingComputer it used this WAF bypass against FBI Jobs.

Why it matters

PeopleSoft is where organizations keep the records people least want leaked: payroll, HR files, student data, bank details for direct deposit. ShinyHunters runs data-theft extortion, and Google tells affected organizations to prepare for ransom notes and possible publication of stolen data.

The bigger lesson is about “mitigated” tickets. Plenty of teams closed this one in June with a WAF rule and moved on. That rule may still show green in every dashboard while the hub behind it is reachable. If the risk register says “mitigated by WAF,” it needs a second look.

What to do first

Forward this

If your organization runs Oracle PeopleSoft for HR, payroll, finance, or student records: please confirm this week that Oracle’s June 10 security fix is actually installed, not just blocked at the firewall. Google says the ShinyHunters extortion group is getting past firewall rules with a one-letter trick and has planted web shells on dozens of servers. Ask the team that runs PeopleSoft for a yes or no, and whether the Environment Management Hub can be switched off.

Details

Hunt / verify

Slack paste: PeopleSoft: confirm Oracle’s June 10 fix for CVE-2026-35273 is installed (not just WAF-blocked), disable EMHub/PSEMHUB if unused, grep WebLogic logs for encoded /PSEMHUB/ (e.g. /%50SEMHUB/), check PSEMHUB.war for stray JSPs.

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.