Hacking group ShinyHunters resumed attacks on September 29, 2026, using a one-letter WAF bypass to exploit CVE-2026-35273, a critical Oracle PeopleSoft vulnerability, to plant web shells on unpatched servers.
The ShinyHunters extortion gang exploited a URL-encoding technique to bypass web application firewall protections against CVE-2026-35273 in Oracle PeopleSoft, resuming attacks as of September 28, 2026. Security experts urged organizations to apply available patches.