ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
Summary
The ShinyHunters extortion gang is actively exploiting a vulnerability in Oracle PeopleSoft by using a URL-encoding trick to bypass Web Application Firewall (WAF) rules designed to mitigate the CVE-2026-35273 flaw. This bypass allows them to resume widespread exploitation of vulnerable servers.
IFF Assessment
The article details how a threat actor is exploiting a vulnerability in a popular enterprise application, indicating a negative impact on defenders.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: June 15, 2026. Known ransomware use: Known.
Defender Context
This incident highlights the ongoing challenge of securing enterprise applications like Oracle PeopleSoft. Defenders need to ensure that WAF rules are not only in place but also robust enough to withstand common obfuscation techniques like URL encoding, and that patches for known vulnerabilities are applied promptly.