Google Warns: Oracle PeopleSoft Flaw Exploited in New Wave of Attacks

·
Listen to this article~4 min
Google Warns: Oracle PeopleSoft Flaw Exploited in New Wave of Attacks

Google warns of renewed mass exploitation of a critical Oracle PeopleSoft flaw (CVE-2026-35273) linked to ShinyHunters. Attackers are bypassing WAFs and deploying web shells. Here's what you need to know and how to protect your systems.

### The WAF That Wasn't Enough Google just dropped a warning that should make any security team sit up straight. A known Oracle PeopleSoft vulnerability is being exploited again, and this time it's happening at scale. The campaign is hitting multiple sectors globally, and the attackers aren't being subtle about it. At the heart of this is CVE-2026-35273, a critical flaw with a CVSS score of 9.8. That's about as bad as it gets. It allows unauthenticated remote code execution, which is a fancy way of saying someone can run their own code on your server without ever logging in. No password. No credentials. Just a direct line into your system. ### What's Actually Happening The activity has been linked to ShinyHunters, a group that's been making noise for a while now. They're weaponizing this flaw and deploying web shells, which are basically backdoors that let attackers keep coming back whenever they want. Here's the kicker: this vulnerability was first exploited as a zero-day. That means the bad guys knew about it before Oracle did. They had a head start, and they used it. > "The window between disclosure and exploitation is shrinking to almost nothing. If you're not patching within hours, you're already behind." ### Why This Matters for Your Business If you're running Oracle PeopleSoft, you need to pay attention. This isn't some theoretical risk. It's happening right now, and the attackers are targeting organizations across industries. Here's what you should be thinking about: - **Patch immediately.** If you haven't applied the latest security updates, do it now. Not tomorrow. Now. - **Check for web shells.** Attackers who've already gotten in will leave these behind. Look for unusual files or processes on your servers. - **Review your WAF rules.** The fact that attackers are bypassing WAFs means your current configuration might not be enough. Consider tightening things up. - **Monitor outbound traffic.** Web shells often communicate with command-and-control servers. Unusual outbound connections could be a red flag. ### The Bigger Picture This isn't just about one vulnerability. It's a reminder that security is a moving target. The tools and tactics attackers use evolve constantly, and the defenses that worked last year might not cut it today. For those of us in the antidetect browser space, this story hits close to home. We spend our days thinking about how to protect identities and prevent unauthorized access. Seeing a flaw like this exploited so aggressively is a wake-up call. It's not enough to have a good defense. You need to have layers of defense, and you need to assume that at some point, something will get through. The best antidetect browser in the world won't save you if your underlying systems are vulnerable. Security is holistic. It's about people, processes, and technology all working together. ### What Comes Next Google's warning is a signal that this campaign is active and ongoing. If you're in the crosshairs, you need to act fast. Even if you're not, it's a good time to review your incident response plan and make sure you're ready for the next big thing. Because there will be a next big thing. There always is.