By Interestana AI Editorial — AI-drafted, human-overseen. How we report
ShinyHunters Exploits Oracle PeopleSoft Vulnerability
The ShinyHunters extortion gang has resumed widespread exploitation of the Oracle PeopleSoft CVE-2026-35273 vulnerability by employing a URL-encoding trick to bypass web application firewall (WAF) rules. This tactic allows the threat actors to circumvent security measures designed to mitigate the flaw, enabling them to compromise vulnerable Oracle PeopleSoft instances. The CVE-2026-35273 flaw, identified as a critical vulnerability, affects Oracle's PeopleSoft enterprise resource planning (ERP) software, which is utilized by numerous organizations globally for managing human resources, financial, and operational processes. By successfully bypassing WAF protections, ShinyHunters can gain unauthorized access to sensitive data and systems hosted on these vulnerable servers. The group's modus operandi typically involves exfiltrating data and then demanding ransom payments from affected organizations to prevent its public release. The use of a URL-encoding bypass is a sophisticated technique that manipulates how web servers interpret requests, often by encoding special characters within URLs. Attackers exploit this by crafting malicious requests that appear benign to standard WAF inspection but are interpreted differently by the underlying application server, thereby allowing the exploit to proceed. This method highlights the ongoing cat-and-mouse game between threat actors and cybersecurity defenders, where attackers continuously develop new techniques to circumvent existing security controls. Oracle PeopleSoft is a widely adopted platform, meaning that a successful exploitation campaign could impact a significant number of businesses across various sectors, including higher education, government, and large corporations. The exploitation of this specific vulnerability, CVE-2026-35273, underscores the importance of timely patching and robust security configurations for ERP systems. Organizations relying on Oracle PeopleSoft are strongly advised to ensure their systems are updated with the latest security patches released by Oracle and to review their WAF configurations to detect and block such bypass techniques. The ongoing activity by ShinyHunters serves as a stark reminder of the persistent threat posed by cybercriminal groups and the need for continuous vigilance in the cybersecurity landscape. The group's ability to adapt its methods to overcome security barriers indicates a high level of technical proficiency and a persistent drive to monetize their exploits through extortion. The implications of such attacks extend beyond data theft, potentially leading to significant operational disruptions, financial losses, and reputational damage for the victimized organizations. The effectiveness of the URL-encoding bypass suggests that WAFs alone may not be sufficient, and a layered security approach, including intrusion detection and prevention systems, regular vulnerability assessments, and employee security awareness training, is crucial for comprehensive protection against evolving threats.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.