ShinyHunters (UNC6240) renewed exploitation of CVE-2026-35273 in Oracle PeopleSoft, bypassing WAF rules through URL-encoding and targeting multiple sectors globally including education, healthcare, and government. The threat actor adapted to published defenses by modifying exploits to reach the vulnerable PSEMHUB endpoint on unpatched systems.