ShinyHunters, the extortion crew behind some of this year’s biggest breaches, has found a way back in — and the trick fits inside a single character. According to Reuters, Google’s cybersecurity unit said Friday that the group has renewed “mass exploitation” of a critical flaw in Oracle’s PeopleSoft software, slipping past the very defenses that were put in place after attacks this summer.
That’s bad news for the thousands of large organizations that run payroll, benefits, and HR records on PeopleSoft — and for the IT teams who thought a firewall rule had bought them time.
One Character Was All It Took
The bypass is almost embarrassingly simple. Google’s threat-intelligence team wrote in a report published Friday that the attackers defeated string-based firewall rules by URL-encoding a single letter: they requested /%50SEMHUB/ instead of /PSEMHUB/, the vulnerable PeopleSoft endpoint.
To a human reader the two look nearly identical. To a web application firewall matching the literal text before decoding, they are completely different requests — and the PeopleSoft application server happily decodes the request and routes it straight to the vulnerable servlet. One encoded letter P, and the firewall might as well not exist.
Mandiant’s blunt takeaway: “WAF rules and path-based blocking are not a substitute for patching.”
From Zero-Day to N-Day
This isn’t a new bug. The flaw, tracked as CVE-2026-35273, was exploited as a zero-day between May 27 and June 9, mostly against universities. Oracle shipped an out-of-band Security Alert on June 10, and Google’s June guidance told organizations to patch — suggesting perimeter blocking of the vulnerable endpoint only as a stopgap.
Plenty of organizations took the stopgap and skipped the patch. Mandiant says the hackers studied the published defensive guidance and deliberately aimed at exactly those organizations: the ones that had implemented firewall rules but never applied Oracle’s update.
The new wave has planted web shells on dozens of systems worldwide across higher education, technology, IT services, healthcare, agriculture, transportation, and government. Google found files named x.jsp and u.jsp for command execution and file uploads, a trojanized installer carrying a backdoor dubbed SIDEEYE, plus tunneling tools for moving laterally inside networks. About a quarter of the attacker’s commands ran as root or SYSTEM — full control of the host.
The FBI Claim Nobody Can Confirm
The report landed days after ShinyHunters claimed it had stolen FBI personnel data, including names of staff in sensitive units and medical records. Reuters, which reported those details earlier, says it has not been able to corroborate the group’s claim. The FBI said Wednesday it is “aggressively investigating” the reported breach. Oracle did not respond to requests for comment.
Until someone independently verifies it, the FBI claim stays in the same bucket as every other hacker boast: plausible, alarming — and unconfirmed. The same caution applies to the group’s fast-growing reputation as the crew that hit Salesforce customers, universities, and now federal targets in a single year.
Why This Matters
The real lesson here isn’t about Oracle. It’s about the most common security posture in corporate IT: patching deferred, a firewall rule added, checkbox ticked.
ShinyHunters didn’t find a new vulnerability. They read the defense everyone was told to deploy, found the one-character gap in it, and aimed squarely at the organizations that had done the easy part but not the important one. Mandiant’s data makes the point uncomfortably clear: the middle ground isn’t safer than doing nothing. It’s a bullseye.
For IT teams the fix is concrete: apply Oracle’s patch for CVE-2026-35273, disable or remove the PSEMHUB service if it isn’t needed, and hunt WebLogic logs for /%50SEMHUB/ and any percent-encoded variant — not just the plain path. A rule that matches text before decoding is decoration.
Meanwhile in Tech News: Google Confirms Customer Data Stolen via Salesforce Breach — the same ShinyHunters collective’s earlier Salesforce campaign and Trump Calls Tech CEOs to the Table: AI Meeting With Speaker Johnson Set for September 29.


