ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

The ShinyHunters extortion gang is using a URL-encoding trick to bypass WAF rules protecting Oracle PeopleSoft servers from the CVE-2026-35273 vulnerability. Experts urge organizations to apply the latest security updates rather than relying on firewall mitigations to prevent further data theft and web shell deployments.

Edward Kiledjian @ekiledjian