ShinyHunters, a well‑known extortion gang, has resumed widespread attacks on Oracle PeopleSoft servers by employing a URL‑encoding trick that bypasses web application firewall (WAF) rules designed to mitigate the CVE‑2026‑35273 vulnerability.
The CVE‑2026‑35273 flaw, which affects Oracle PeopleSoft applications, has been a target for attackers seeking to gain unauthorized access. ShinyHunters’ new technique encodes malicious URLs in a way that slips past WAF defenses, allowing the gang to exploit the vulnerability on vulnerable servers once again.
Oracle PeopleSoft is a widely used suite of enterprise software, and the re‑emergence of this exploit underscores the importance of keeping security controls up to date. The WAF bypass demonstrates that even established mitigation measures can be circumvented with relatively simple encoding tricks.
Security analysts warn that organizations running Oracle PeopleSoft should verify that their WAF rules are correctly configured and consider applying any available patches for CVE‑2026‑35273. Failure to do so could leave systems exposed to continued exploitation and potential ransom demands from ShinyHunters.
<small>Source: Bleeping Computer — read the original story there.</small>