The hacking of the FBI's recruitment portal is beginning to reveal its first technical details. Google has documented a method used by ShinyHunters to bypass Oracle PeopleSoft protections, which the group claims it also used against FBI Jobs. A few days after the claimed attack against the FBI, new elements allow a better understanding of how ShinyHunters might have reached the Oracle PeopleSoft environment used by the agency's recruitment portal. Google researchers have identified a technique used by the group to bypass temporary measures deployed on servers that had not yet installed the patch published by Oracle in June for a critical PeopleSoft vulnerability.
The incident dates back to late spring. ShinyHunters begins to infiltrate Oracle PeopleSoft servers through a vulnerability that is still unpatched and not yet publicly disclosed. For nearly two weeks, the group can exploit it without a patch being available, notably against higher education institutions. Oracle eventually intervenes on June 10 and assigns the vulnerability the reference CVE-2026-35273. This critical vulnerability allows remote code execution on a server without requiring credentials. However, the publication of the patch does not immediately resolve the problem for all affected organizations. The time needed to test and deploy the update leaves some servers vulnerable and requiring alternative protection.
Among the recommended measures is blocking, at the application firewall level, the address that allows access to the vulnerable part of PeopleSoft from the Internet. The vulnerability is therefore still present on the machine, but requests coming from the outside are supposed to no longer be able to reach it. ShinyHunters therefore adapts its exploit. Instead of directly targeting /PSEMHUB/, the address that firewalls have been configured to block, the group sends its requests to /%50SEMHUB/. However, in a URL, %50 corresponds to the uppercase letter P. For the firewall, which can examine the address before decoding it, the path is no longer the one specified in the blocking rule. For Oracle WebLogic, which then proceeds to decode, /%50SEMHUB/ becomes /PSEMHUB/ again and directs the request to the vulnerable component that the firewall was supposed to prevent from being reached from the Internet.
This is presumably what also happened on FBI Jobs. ShinyHunters claims to have used the same bypass against the FBI's recruitment portal, while maintaining that it exploited a second unknown vulnerability in the same part of PeopleSoft. The FBI has confirmed it is investigating the claimed compromise of FBI Jobs, but has not publicly established the entry point used by the attackers. The choice of target was not accidental. In claiming the attack, ShinyHunters presented it as a measure of retaliation against a bulletin published by the FBI in May, which detailed its methods and attributed to it notably harassment, threats, and swatting practices. The group disputes these allegations and demands that the agency correct or remove the document. It also stated that the operation had no financial motivation and did not request any ransom.
FBI Investigates Alleged Cyberattack on Recruitment Portal by ShinyHunters Group
AI-rewritten from original reportingHow it works
cybersecurityfbioracle-peoplesoftshinyhuntershackingcve
Original sources:
- 🇫🇷Clubic



