Log In
softwarebay.de
softwarebay.de
ShinyHunters Exploits WAF Bypass in Oracle PeopleSoft Attack
News › Cybersecurity › ShinyHunters Exploits WAF Bypass in Oracle PeopleS...
Cybersecurity

ShinyHunters Exploits WAF Bypass in Oracle PeopleSoft Attacks

ShinyHunters Exploits WAF Bypass in Oracle PeopleSoft Attacks

The ransomware group ShinyHunters has developed a new trick to circumvent the security measures of Oracle PeopleSoft. By utilizing a URL encoding technique, the attackers are able to bypass the rules of Web Application Firewalls (WAF) that were specifically implemented to mitigate the vulnerability CVE-2026-35273. This vulnerability allows unauthorized access to susceptible servers, compromising them. Attacks on Oracle PeopleSoft have increased in recent weeks, with ShinyHunters employing a variety of techniques to achieve their objectives. The group is known for its aggressive extortion strategies, which often involve the release of sensitive data to exert pressure on the affected companies.

The current method poses a serious threat to organizations using this software. The vulnerability CVE-2026-35273 particularly affects authentication, enabling attackers to gain unauthorized access. Security researchers have found that exploiting this vulnerability in combination with the URL encoding trick significantly reduces the effectiveness of WAFs. This results in many companies being inadequately protected, increasing the likelihood of a successful attack. The security community has already responded to the threat and recommends that companies promptly update their systems to the latest version of Oracle PeopleSoft.

Implementing additional security measures, such as Intrusion Detection Systems (IDS), is also advised to detect potential attacks early. Experts warn that without these measures, the risk of data loss or system compromise significantly increases. ShinyHunters has previously conducted several high-profile attacks, including on large companies and institutions. The group has built a reputation for its ability to bypass security measures and steal sensitive information. The current campaign against Oracle PeopleSoft could prove to be one of the most extensive in the group's history.

The threat posed by ShinyHunters has also attracted the attention of law enforcement agencies. They are working to monitor the group's activities and identify potential members. International cooperation among authorities could be crucial in stopping the group and holding those responsible accountable. The vulnerability CVE-2026-35273 was discovered in August 2026 and affects a variety of versions of Oracle PeopleSoft. The exact number of affected systems is currently unknown; however, experts estimate that several thousand companies worldwide are at risk.

The urgency of implementing security updates is therefore of utmost importance. The attacks by ShinyHunters demonstrate how critical it is to regularly review and update security protocols. Companies are urged to strengthen their security architecture and ensure that all employees are informed about the latest threats. A proactive approach to cybersecurity can be vital in preventing future attacks. The security situation remains tense as ShinyHunters continues to be active.

The group has announced plans to expand its attacks, increasing the need for companies to better protect themselves. Security researchers advise utilizing all available resources to secure systems and fend off potential attacks. The threat from ShinyHunters and the exploitation of CVE-2026-35273 highlight the challenges companies face in today’s digital landscape. The necessity to implement and maintain security measures is essential to ensure the integrity of systems. According to recent reports, over 30% of companies using Oracle PeopleSoft are already affected by this vulnerability.

Tags: Cybersecurity Oracle ShinyHunters CVE-2026-35273 PeopleSoft WAF

💬 Comments (0)

Write a comment

info Will be published after moderation
chat_bubble_outline

No comments yet. Be the first to comment!