Vulnerabilities · InfosecFeed Brief

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

Vulnerabilities

What you need to know

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. [...]

Source transparency

This is an InfosecFeed curated brief based on reporting from BleepingComputer. InfosecFeed does not claim ownership of the original reporting.

Read the original report at BleepingComputer ↗