ShinyHunters has resumed large-scale attacks against Oracle PeopleSoft, bypassing web application firewall rules with a minor tweak to its exploit This article explores attacks oracle peoplesoft. . Mandiant and Google Threat Intelligence Group (GTIG) reveal the group, identified as UNC6240, has deployed web shells on multiple systems worldwide.
The latest targets include higher education, technology, IT services, healthcare, agriculture, transportation, and government. Oracle issued an emergency security alert on June 10, 2026. This sequence, %50, represents the letter "P." A WAF rule that only looks for the literal /PSEMHUB/ path may miss the encoded request, while the PeopleSoft server decodes it and sends it to the vulnerable Environment Management Hub endpoint.
Security teams should review WebLogic access logs for URLs like /PSEMHUB/, their encoded counterparts such as /%50SEMHUB/, suspicious POST requests to /hub, and unexpected JSP requests. They should scrutinize every WebLogic node for unfamiliar files, including x.jsp, u.jsp, tunnel.jsp, and Ple64.exe, and investigate any Java-based shell processes. Indicators of Compromise Type Indicator Reported role IPv4 5.199.162.157 Attack controller, scanner, and HTTP callback receiver IPv4 104.219.234.138 Exfiltration staging and remote management host Join 16,000+ SOC teams using ANY.RUN to enhance threat investigations and decrease manual workload.











