Cyber threat intelligence reports confirm that extortion group ShinyHunters, tracked as UNC6240, successfully breached government cloud storage repositories by bypassing firewall rules protecting enterprise software deployments. The group leveraged character encoding tricks to reach vulnerable web endpoints without triggering security signatures.
The attack campaign abused Oracle PeopleSoft vulnerability CVE-2026-35273 with a CVSS score of 9.8. Threat actors modified URI request parameters using URL-encoded character substitutions slash percent-50-SEMHUB slash to evade string-matching web application firewall rules. After achieving unauthenticated remote code execution on the PeopleSoft server, the group pivoted into adjacent AWS government cloud storage repositories, exfiltrating terabytes of sensitive administrative records and issuing formal extortion demands.
Relying on signature-based firewall rules without underlying vendor patches introduces severe enterprise cloud security risks. When threat actors bypass perimeter firewall filters to compromise web applications, unmonitored server access enables adversaries to harvest integration tokens and pivot directly into cloud production storage.
– Apply official security patches published by Oracle across all PeopleSoft application server installations immediately.
– Reconfigure web application firewalls to perform full URI path decoding before evaluating pattern-matching security rules.
– Inspect cloud storage access logs and identity session tokens for unverified file access calls originating from application hosts.
– Disable the Environment Management Hub service in multi-server setups or remove the PSEMHUB application in single-server setups.
Enterprise cloud application security requires complete vendor patch deployment and thorough path decoding to ensure business portals remain insulated from unauthenticated remote code execution. #CodeDefence #Oracle #PeopleSoft #ShinyHunters #UNC6240 #WAFBypass #CloudSecurity #RCE #DataExfiltration
/
