ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
The ShinyHunters extortion gang is bypassing Web Application Firewall (WAF) rules by using URL-encoding tricks to exploit the Oracle PeopleSoft CVE-2026-35273 vulnerability. Mandiant urges organizations to apply the official security update rather than relying on WAF blocks, as attackers continue to deploy web shells and malware to steal sensitive data.