vulnerabilityransomware
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
September 27, 2026
Back to all postsThe ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.
Source: BleepingComputer
vulnerabilityransomware
Concerned about this threat to your business?
We help Canadian SMBs deploy the controls discussed in this article. Free 30-minute assessment — no obligation.
