vulnerabilityransomware

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

September 27, 2026

Back to all posts

Source: BleepingComputer

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.
vulnerabilityransomware

Concerned about this threat to your business?

We help Canadian SMBs deploy the controls discussed in this article. Free 30-minute assessment — no obligation.

Book a free assessment