ShinyHunters exploits PeopleSoft vulnerability with WAF bypass technique
Hacking group ShinyHunters resumed attacks on September 29, 2026, using a one-letter WAF bypass to exploit CVE-2026-35273, a critical Oracle PeopleSoft vulnerability, to plant web shells on unpatched servers.