ShinyHunters exploits PeopleSoft vulnerability with WAF bypass technique

Hacking group ShinyHunters resumed attacks on September 29, 2026, using a one-letter WAF bypass to exploit CVE-2026-35273, a critical Oracle PeopleSoft vulnerability, to plant web shells on unpatched servers.

2 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

ShinyHunters PeopleSoft attacks are back. A one-letter WAF bypass lets the group exploit CVE-2026-35273 and plant web shells on unpatched servers. # ShinyHunters # PeopleSoft # WAFBypass # CVE20263527

mastodon:infosec-exchangeother68m ago kagi ↗

ShinyHunters PeopleSoft attacks are back. A one-letter WAF bypass lets the group exploit CVE-2026-35273 and plant web shells on unpatched servers. # ShinyHunters # PeopleSoft # WAFBypass # CVE202635273 # UNC6240 # Oracle # DataExtortion # CyberSecurity https:// securityonline.info/shinyhunte rs-peoplesoft-attacks/?utm_source=mastodon&utm_medium=jetpack_social

Discover how ShinyHunters uses URL encoding to bypass WAF defenses, aggressively exploiting the critical CVE-2026-35273 Oracle PeopleSoft vulnerability. # ShinyHunters # OraclePeopleSoft # WAFBypass #

mastodon:infosec-exchangeother62m ago kagi ↗

Discover how ShinyHunters uses URL encoding to bypass WAF defenses, aggressively exploiting the critical CVE-2026-35273 Oracle PeopleSoft vulnerability. # ShinyHunters # OraclePeopleSoft # WAFBypass # CyberSecurity # ZeroDay https:// meterpreter.org/shinyhunters-o racle-peoplesoft-waf-bypass/?utm_source=mastodon&utm_medium=jetpack_social