decrypted · 28 september 2026 · ransomware and cybercrime · vulnerabilities and patching · ai and llm security

ShinyHunters walks round the PeopleSoft firewall fix with one character

Firewall rules are meant to buy you time while you patch. This week Google's Mandiant team reported that ShinyHunters, the data-theft extortion gang, has walked round the firewall rules some organisations put in front of Oracle PeopleSoft after June's zero-day. It took one changed character in a web address. The flaw is the same and the gang is the same, and June's victims included a UK university. What is new is that the workaround some teams trusted does not hold.

The trick, in plain English

The flaw, CVE-2026-35273, is a critical bug (scored 9.8) in PeopleSoft's Environment Management Hub, known as PSEMHUB. It lets an unauthenticated attacker run commands on the server. Mandiant dates exploitation from 27 May to 9 June, before Oracle's fix arrived in June. Some teams relied on a web application firewall rule blocking requests to /PSEMHUB/ as a mitigation.

The bypass is almost comically small. Attackers now request /%50SEMHUB/, where %50 is just the letter P in URL encoding. Picture a doorman checking a guest list against the name exactly as spoken. Give him a slightly different spelling and he waves you through, while the receptionist inside understands perfectly well who you mean. The firewall compared the raw text; the PeopleSoft server decoded it first.

Mandiant says the gang then planted web shells, a tunnelling tool and a remote management agent on dozens of systems worldwide, across higher education, technology, IT services, healthcare, agriculture, transport and government.

The UK cost

June showed what is at stake. ShinyHunters used the same bug against the University of Nottingham, which confirmed that a well-known criminal group had accessed a significant amount of data in its student record system. Reporting put the figure at more than 450,000 current and former students, with passport numbers, ethnicity, disability information and fee payments among the fields. The university said it had reported the incident to the ICO and Action Fraud, and the gang published the files.

Google's new report names no UK victims in this wave. That is not the same as there being none, and any UK organisation running PeopleSoft's web tier should assume it has been scanned.

The Secure by Design lesson

A firewall rule is a compensating control, and compensating controls fail quietly. Google's advice is blunt: WAF rules and path blocking are not substitutes for the patch. Three design decisions would have blunted this:

The cost is modest. Patching is a maintenance window and removing an unused hub is an afternoon. Then search logs for /PSEMHUB/ and its percent-encoded variants, and check the PSEMHUB.war directory for files that should not be there, such as x.jsp.

A useful question for the next board pack: are we patched, or merely filtered? If the honest answer is a rule set, you have bought time, not safety. Opinion, not advice.

Also this week

AI security: SalesBleed. Zenity Labs disclosed three flaws in Salesforce's Agentforce. An attacker could hide instructions in an ordinary Web-to-Lead form, and they lay dormant until an employee asked an agent about that lead. The agent could then send CRM data to the attacker's server with no click, or phish colleagues through a trusted Slack identity. Salesforce has fixed all three. Zenity's point is the design lesson: any agent that reads outside input, renders links and holds access to sensitive data has all three ingredients in one place. Secure by Design here means keeping untrusted text away from the keys.

Cloud: a forged token opened Microsoft's Titan. A 16-year-old researcher known as Faav reported that Microsoft's internal Titan analytics service accepted login tokens without checking their signature. A forged token naming the user as "admin" gave administrator access to a database query interface covering roughly 17 trillion rows, including some 18,000 staff email records. Faav says they confirmed access through metadata rather than extracting customer data, and reports that Microsoft locked the endpoint down within days. It was Microsoft's own data, but the lesson travels: a token is only as good as the signature check, and that check belongs in the default path, not on a review checklist.

UK policy: the ICO becomes a board. On Wednesday 30 September the Information Commissioner's Office becomes the Information Commission, a board-led body, under the Data (Use and Access) Act 2025. Seven non-executive members appointed in July take their seats, and the ICO says it will still be known as the ICO. Its functions and responsibilities carry on, so this looks like continuity rather than new obligations. What does change is that the regulator you notify after a breach like Nottingham's will decide collectively rather than through a single commissioner.

Sources

Not sure what your organisation exposes to the internet? get in touch and we will take a look with you.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.