Cyber threat intelligence advisories published today warn of widespread wild attack campaigns targeting enterprise resource planning portals. Threat actors modify public exploit scripts to bypass web application firewall rules, deploying tunneling tools and remote management agents for mass data extortion.
The attack campaign targets Oracle PeopleSoft installations via vulnerability CVE-2026-35273 with a CVSS score of 9.8. Adversaries associated with threat group UNC6240 bypass string-matching WAF rules by URL-encoding path characters, submitting requests to slash percent-50-SEMHUB slash to reach vulnerable Environment Management Hub endpoints. Upon gaining unauthenticated remote code execution, threat actors deploy Neo-reGeorg tunneling toolkits, MeshAgent remote management software, and persistent web shells, escalating execution rights to root and NT AUTHORITY SYSTEM.
Subverting enterprise resource planning applications exposes central database archives and sensitive corporate records. Because PeopleSoft installations govern human resources data, financial accounting tables, and executive records, an unauthenticated host compromise permits threat actors to exfiltrate gigabytes of corporate records for extortion campaigns.
– Force immediate security patch installation published by Oracle across all PeopleSoft application server deployments.
– Disable the Environment Management Hub service in multi-server setups or remove the PSEMHUB application in single-server environments.
– Update web application firewall inspection engines to perform full URL-decoding prior to evaluating path-matching rules.
– Inspect application hosting directories for unauthorized web shells, Neo-reGeorg scripts, or unverified MeshAgent binary executions.
Enterprise resource planning defense relies on strict WAF path decoding and rapid vendor patch execution to ensure central business portals remain protected from unauthenticated remote code execution. #CodeDefence #Oracle #PeopleSoft #ShinyHunters #WAFBypass #RCE #DataExtortion #AppSec #PatchManagement
/
