How Attackers Are Slipping Past Defenses to Hit Oracle Systems

·
Listen to this article~5 min
How Attackers Are Slipping Past Defenses to Hit Oracle Systems

Google warns of a major global hacking campaign exploiting a critical Oracle PeopleSoft flaw (CVE-2026-35273) to remotely take over systems, bypassing key security defenses.

Google's security team is sounding the alarm again, and this time it's about something many hoped was in the past. They're tracking a massive, renewed wave of attacks exploiting a known flaw in Oracle PeopleSoft software. These aren't small-time hackers; they're sophisticated groups linked to ShinyHunters, and they're targeting organizations across multiple sectors worldwide. It feels like we just patched this, doesn't it? But that's the tricky part about cybersecurity threats—they often circle back when you least expect them, especially when attackers find new ways to get in. ### What's the Flaw Everyone's Worried About? The attackers are weaponizing a specific vulnerability tracked as CVE-2026-35273. Now, that's just a string of letters and numbers, but what it represents is serious. It has a CVSS score of 9.8 out of 10. For those not steeped in security jargon, that's about as critical as it gets. A score that high means it's relatively easy to exploit and the potential damage is severe. In plain English, this flaw could allow someone to execute remote code on a PeopleSoft system without needing any login credentials. They don't need a username or password. If your system is vulnerable and exposed, they can potentially take control. The scariest part? This was first exploited as a zero-day, meaning attacks were happening before a fix was even available. ### How Are They Getting Through the Defenses? Here's where it gets clever, and frankly, a bit unsettling. The original reports mentioned attackers bypassing Web Application Firewalls (WAFs). Think of a WAF like a highly trained bouncer at a club's door, checking IDs and looking for trouble. These attackers aren't trying to fight the bouncer; they're finding a side door he's not watching. They're using advanced techniques to make their malicious traffic look like normal, everyday web requests. It's the digital equivalent of wearing a perfect disguise. This allows them to slip past the very security measures designed to stop them, directly to the vulnerable PeopleSoft component. Once they're in, their goal is often to deploy what's called a web shell. This isn't a physical object; it's a small piece of malicious code uploaded to the server. It acts like a secret backdoor, giving the attackers persistent access to the system. They can come and go, steal data, or use the compromised server as a launching point for attacks deeper into the network. ### Why Should This Matter to You? You might be thinking, "I don't use Oracle PeopleSoft, so I'm fine." But the principles at play here are what matter. This campaign highlights a few critical trends in modern cyber attacks: - **The Re-exploitation of Old Vulnerabilities:** Patches exist for this flaw, but not every organization has applied them. Attackers constantly scan the internet for unpatched, known vulnerabilities. It's low-hanging fruit for them. - **Evasion is the New Normal:** Simply having a firewall or basic security isn't enough. Adversaries are adept at crafting attacks that avoid signature-based detection. - **The Supply Chain Risk:** PeopleSoft is enterprise software used by large organizations in government, healthcare, finance, and education. A breach at a software vendor or a commonly used platform can have ripple effects across countless businesses. So, what can you do? It's less about a single action and more about a mindset. Assume that patches for critical vulnerabilities need to be applied immediately, not when it's convenient. Understand that layered security—detection, response, and hardening—is better than relying on any single solution. As one security expert I spoke to recently put it: "Defense isn't a product you buy; it's a process you live. The attackers only need to be right once. You need to be right every single time." That sums up the challenge perfectly. This ongoing campaign against Oracle PeopleSoft isn't just a news story. It's a reminder to audit your own systems, check your patch levels, and remember that in cybersecurity, the past has a way of coming back to haunt the present.