Hackers Slip Past WAFs to Drop Web Shells in Oracle PeopleSoft

·
Listen to this article~4 min
Hackers Slip Past WAFs to Drop Web Shells in Oracle PeopleSoft

Google warns of renewed mass exploitation of a critical Oracle PeopleSoft flaw. Attackers are bypassing WAFs and deploying web shells. Here's what you need to know.

Google just dropped a warning that should make anyone running Oracle PeopleSoft sit up straight. A known vulnerability is being exploited again — at scale — and attackers are deploying web shells across multiple sectors worldwide. If you thought that patch from months ago closed the door, think again. ### What's Actually Happening The flaw in question is CVE-2026-35273, and it carries a CVSS score of 9.8. That's about as bad as it gets. It allows unauthenticated remote code execution, which is a fancy way of saying someone can run whatever code they want on your server without even logging in. Security researchers have linked this activity to ShinyHunters, a group that's been busy. They're not just poking around — they're bypassing Web Application Firewalls (WAFs) that many organizations rely on for protection. That's the scary part. You can have all the perimeter defenses in the world, but if attackers know how to slip past them, those defenses become little more than a speed bump. The vulnerability was first exploited as a zero-day, meaning the bad guys got to it before Oracle even had a patch ready. Now, even with fixes available, unpatched systems are sitting ducks. ### Why WAFs Aren't Enough Here's the thing about WAFs — they're designed to catch known attack patterns. They look for suspicious traffic and block it. But skilled attackers don't send suspicious traffic. They craft requests that look perfectly legitimate until it's too late. > "The assumption that a WAF will catch everything is one of the most dangerous beliefs in security today." — Anonymous security researcher Once inside, attackers deploy web shells — small scripts that give them persistent remote access. Think of it like leaving a back door unlocked in a building you've already broken into. They can come and go as they please, often without triggering alarms for weeks or months. ### What You Should Do Right Now If you're running PeopleSoft, don't wait. Here's a quick checklist: - Apply the latest Oracle patches immediately — no exceptions - Audit your systems for signs of web shells or unusual file changes - Review WAF logs for anomalies, but don't trust them as your only defense - Segment your network so a single breach doesn't compromise everything - Monitor outbound traffic — web shells often phone home to command servers The broader lesson here? Security isn't a product you buy. It's a practice you maintain. WAFs, firewalls, antivirus — they're all tools. But tools don't think. Attackers do. And they're constantly adapting. ### The Bigger Picture This isn't just about Oracle PeopleSoft. It's about a mindset. Too many organizations treat security as a checkbox — install this, configure that, done. But the threat landscape shifts daily. What worked last year might be useless today. The ShinyHunters campaign is a reminder that attackers are patient. They study your defenses. They find the gaps. And when they strike, they strike hard. So yes, patch your systems. But also ask yourself: what else are you assuming is safe? Because that assumption might be exactly what someone's counting on.