Cybersecuritynews iconCybersecuritynewsSep 28, 2026

ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

ShinyHunters has renewed attacks against Oracle PeopleSoft systems by slipping past web application firewall protections and planting web shells. The campaign shows how a small change in an attack request can reopen exposure that administrators believed had been contained.

ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Share this story

Send the public story page.

Useful takeaways from this story.

ShinyHunters has renewed attacks against Oracle PeopleSoft systems by slipping past web application firewall protections and planting web shells.

The campaign shows how a small change in an attack request can reopen exposure that administrators believed had been contained.

The activity targets CVE-2026-35273, a critical PeopleSoft flaw previously used as a zero-day against universities.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

ShinyHunters has renewed attacks against Oracle PeopleSoft systems by slipping past web application firewall protections and planting web shells. The campaign shows how a small change in an attack request can reopen exposure that administrators believed had been contained. The activity targets CVE-2026-35273, a critical PeopleSoft flaw previously used as a zero-day against universities.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app