Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
AI-Powered Attack Tool Exposed: Threat Actors Left Control Panel Unsecured
September 28, 2026
Critical CVE-2023-38408 in libcue Exposes Linux, Windows, macOS Users to Tracking
September 28, 2026
NCSC Urges UK organizations to Patch for Citrix NetScaler ADC and Gateway 0-Day Vulnerabilities
September 28, 2026
Home/Threats/ShinyHunters Exploits Critical Oracle PeopleSoft CVE-2024-21095 to Deploy Web Shells
Threats

ShinyHunters Exploits Critical Oracle PeopleSoft CVE-2024-21095 to Deploy Web Shells

Key Takeaways The ShinyHunters threat group is actively exploiting a critical vulnerability, CVE-2024-21095 (formerly CVE-2026-35273), in Oracle PeopleSoft systems. Attackers are bypassing Web...

Marcus Rodriguez
Marcus Rodriguez
September 28, 2026 4 Min Read
3 0

Key Takeaways

  • The ShinyHunters threat group is actively exploiting a critical vulnerability, CVE-2024-21095 (formerly CVE-2026-35273), in Oracle PeopleSoft systems.
  • Attackers are bypassing Web Application Firewalls (WAFs) by employing a subtle character encoding technique in the request path.
  • The campaign involves deploying web shells and memory-resident backdoors, including the SIDEEYE trojan, across a wide range of sectors.
  • Affected organizations include those in technology, IT services, healthcare, agriculture, transport, and government, impacting systems containing sensitive HR, payroll, and operational data.
  • Oracle has released a security patch for CVE-2024-21095, and immediate application is crucial for internet-facing PeopleSoft deployments.

The notorious ShinyHunters cybercrime group has launched a renewed wave of attacks targeting Oracle PeopleSoft systems, successfully circumventing Web Application Firewall (WAF) protections to install malicious web shells. This sophisticated campaign highlights a critical vulnerability, CVE-2024-21095 (previously identified as CVE-2026-35273), a severe flaw in PeopleSoft that was previously exploited as a zero-day against academic institutions.

Table Of Content

  • Key Takeaways
  • ShinyHunters Bypasses WAF Protections
  • Web Shells Lead to Backdoors
  • What You Should Do

Security researchers at Google Cloud identified this latest mass exploitation effort and have attributed it to the group known as UNC6240, or ShinyHunters. The group’s ability to bypass established perimeter defenses by making minor modifications to attack requests underscores the persistent challenge of relying solely on WAFs without comprehensive software patching.

The current phase of attacks has broadened its scope beyond universities, now impacting organizations across diverse sectors, including technology, IT services, healthcare, agriculture, transportation, and government. These compromised PeopleSoft systems often house sensitive data such as human resources, payroll, and critical operational information, making them high-value targets for attackers.

According to a report from Google Cloud, ShinyHunters has successfully deployed web shells on dozens of systems globally. These web shells serve as initial access points, allowing the attackers to engage in direct, hands-on malicious activities within the compromised environments.

This evolving threat serves as a stark reminder that robust perimeter controls, while important, cannot fully substitute for timely software updates and patching. Previous incidents involving the same PeopleSoft zero-day remote code execution (RCE) vulnerability demonstrated how unauthenticated attackers could gain unauthorized access to exposed enterprise applications before a patch was made available.

ShinyHunters Bypasses WAF Protections

The effectiveness of ShinyHunters’ latest offensive stems from a clever WAF bypass technique. The attackers modified the vulnerable request path by encoding a single character instead of transmitting the standard endpoint name. Many WAFs and reverse proxies inspect incoming requests based on their literal string representation.

However, the Oracle PeopleSoft application server is designed to decode such requests before directing them to the intended service. This discrepancy allows the maliciously crafted, encoded request to slip past WAF rules that would otherwise block the unencoded version, ultimately reaching the vulnerable target. Detailed analysis of this bypass mechanism is available in a technical report.

Before proceeding with full exploitation, ShinyHunters typically sends multiple POST requests containing a serialized Java object. This reconnaissance phase allows them to confirm server vulnerability without necessarily writing files, making detection challenging. Even seemingly failed events in logs could indicate active reconnaissance, urging defenders to scrutinize logs across all nodes, especially in load-balanced environments.

PSEMHUB WAF bypass (Source – Google Cloud)
PSEMHUB WAF bypass (Source – Google Cloud)

Once a system’s vulnerability is confirmed, the attackers proceed to either establish persistent JSP-based web shells or execute commands directly in memory. The former provides a durable backdoor, while the latter can evade file-based security tools by leaving no new files on disk. This stealthy approach underscores the need for organizations to monitor both application and process activity comprehensively.

The current campaign also highlights a broader extortion risk. Past incidents, such as the Nissan PeopleSoft breach, have demonstrated the severe consequences of attackers gaining access to systems containing employee data. In the observed ShinyHunters activity, some commands were executed with root or SYSTEM-level privileges, and attackers gained access to PeopleSoft configuration and database connection details.

Web Shells Lead to Backdoors

On compromised Windows servers, the threat actors employed a secondary web shell to transfer a trojanized installer in segmented chunks, a technique used to circumvent request-size limitations. This installer then deployed the SIDEEYE backdoor into memory. SIDEEYE is a potent tool capable of stealing browser and desktop credentials, managing processes and files, and establishing interactive reverse shells or proxy connections.

Additionally, ShinyHunters utilized tunneling software to route internal network traffic through ordinary web connections. This allowed them to perform internal reconnaissance and move laterally beyond the initial PeopleSoft host. For Linux systems, remote-management tools were deployed to ensure persistence within the environment. This pattern necessitates a thorough investigation by security teams to determine if a PeopleSoft compromise has extended to connected databases or other internal servers. Even if the initial server is secured, a persistent foothold elsewhere could still lead to data exfiltration.

What You Should Do

  • Apply Oracle Patch Immediately: Organizations must apply the Oracle security patch for CVE-2024-21095 without delay. Ensure all PeopleSoft deployments are running supported versions of PeopleTools.
  • Disable or Remove Unnecessary Components: When not actively required, disable the Environment Management Hub. If feasible and appropriate, remove the affected application entirely.
  • Review Access Logs: Scrutinize access logs for any instances of the encoded route (/%50SEMHUB/) and associated external POST requests.
  • Inspect Web Application Directories: Conduct thorough inspections of PeopleSoft web application directories for any unauthorized JSP, JSPX, or executable files.
  • Monitor Process Activity: Configure alerts for command shells spawned by the WebLogic Java process, as these can indicate in-memory exploitation.
  • Incident Response Protocol: If a web shell or compromise is detected, treat it as a full system breach. Preserve forensic evidence, rotate all credentials associated with the application account, and monitor for unusually large outbound data transfers.
  • Database Audit Review: Prepare for potential data theft and extortion by reviewing database audit logs for any bulk exports of sensitive HR, payroll, or student records.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCVEExploitPatchSecurityThreatzero-day

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Attackers Intercept AI Prompts via Fake Jev AI Stores

Next Post

OpenCode AI Coding Agent Flaw Lets Malicious Websites Execute Code

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
ShinyHunters Exploits Critical Oracle PeopleSoft CVE-2024-21095 to Deploy Web Shells
September 28, 2026
Attackers Intercept AI Prompts via Fake Jev AI Stores
September 28, 2026
NVIDIA Unveils Open Safety Platform for Autonomous AI Agents With 100 Partners
September 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us