ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
The notorious extortion gang ShinyHunters is bypassing security defenses to exploit a vulnerability in Oracle PeopleSoft servers.

The notorious ShinyHunters extortion gang has resumed widespread exploitation campaigns targeting the Oracle PeopleSoft software. Threat actors are actively leveraging advanced bypass techniques to breach vulnerable infrastructure.
The attacks specifically target the CVE-2026-35273 flaw in Oracle PeopleSoft. Although web application firewall (WAF) rules were previously implemented to mitigate this security issue, the attackers have found a way around these defenses.
By employing a clever URL-encoding trick, the threat actors manage to bypass WAF mitigation rules successfully. This evasion tactic allows them to slip malicious requests past security filters and continue compromising vulnerable servers.
Incidents like this highlight the persistent threat sophisticated cybercriminal groups pose to enterprise infrastructure globally. Organizations relying on complex enterprise resource software must remain vigilant against evolving exploitation methods.
Security researchers strongly advise administrators to apply the latest patches immediately and update WAF configurations to detect and block URL-encoding evasion techniques used by groups like ShinyHunters.



