⌁ DAY 3

ShinyHunters use URL-encoding WAF bypass on Oracle PeopleSoft CVE-2026-35273

2 beadsSep 26 → Sep 29moved 2h ago

The wire

2026-09-29

ShinyHunters exploits PeopleSoft vulnerability with WAF bypass technique

broke 2h ago · 2 reports · other

Hacking group ShinyHunters resumed attacks on September 29, 2026, using a one-letter WAF bypass to exploit CVE-2026-35273, a critical Oracle PeopleSoft vulnerability, to plant web shells on unpatched servers.

2026-09-26

ShinyHunters use URL-encoding WAF bypass on Oracle PeopleSoft CVE-2026-35273

broke 3d ago · 5 reports · other · tech

The ShinyHunters extortion gang exploited a URL-encoding technique to bypass web application firewall protections against CVE-2026-35273 in Oracle PeopleSoft, resuming attacks as of September 28, 2026. Security experts urged organizations to apply available patches.