A threat actor group UNC6240/ShinyHunters is exploiting CVE-2026-35273 in Oracle PeopleSoft by using URL-encoded characters to bypass Web Application Firewalls, deploying web shells and post-exploitation tools including SIDEEYE across multiple systems.