LOWVulnerability
Global

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

·Source: BleepingComputer

Updated:

Executive Summary

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. [...]

Analysis

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. [...]

Indicators of Compromise (1)

CVE (1)
CVE-2026-35273
Source Attribution

Originally published by BleepingComputer on Sep 26, 2026.

Related Threats