Home / Sep 27, 2026 / Story
0
#2 BleepingComputer general September 26, 2026 at 19:03 UTC

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

By Lawrence Abrams

AI Summary

ShinyHunters is bypassing WAF mitigations for Oracle PeopleSoft CVE-2026-35273 using a URL-encoding trick, effectively re-enabling mass exploitation against servers that were considered protected. This is significant for defenders who applied WAF rules as a temporary mitigation rather than patching, as those controls are now rendered ineffective.

Relevance score: 90.0/100

# More from September 27