ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

The ShinyHunters extortion gang is bypassing Web Application Firewall (WAF) rules by using URL-encoding tricks to exploit the Oracle PeopleSoft CVE-2026-35273 vulnerability. Mandiant urges organizations to apply the official security update rather than relying on WAF blocks, as attackers continue to deploy web shells and malware to steal sensitive data.

Edward Kiledjian @ekiledjian