ShinyHunters Found a Sneaky Way Around Oracle PeopleSoft Defenses

·
Listen to this article~4 min

ShinyHunters is using a URL-encoding trick to bypass WAF rules and exploit Oracle PeopleSoft flaw CVE-2026-35273. Learn how to protect your systems.

The ShinyHunters extortion gang is back at it. This time, they're using a clever URL-encoding trick to slip past web application firewall (WAF) rules that were supposed to block attacks exploiting the Oracle PeopleSoft vulnerability CVE-2026-35273. By encoding malicious requests in a way that WAFs don't catch, they've been able to resume widespread exploitation on vulnerable servers. If you're running PeopleSoft, this is your wake-up call. ### What Exactly Is the Trick? WAFs are like security guards at the door. They check incoming traffic for known bad patterns. But ShinyHunters figured out that if you encode parts of a malicious request—say, turning characters into their percent-encoded equivalents—the WAF might not recognize the threat. It's like writing a threatening note in a secret code that the guard can't read. Once the request reaches the server, it gets decoded and executed anyway. This isn't a new idea, but it's effective. And it's why relying solely on a WAF is a bit like locking your front door but leaving the windows open. ### Why Should You Care? If your organization uses Oracle PeopleSoft—and many large enterprises do—you're at risk. The CVE-2026-35273 flaw allows attackers to execute code remotely, which means they could take control of your system, steal data, or worse. ShinyHunters is known for extortion: they breach systems, steal sensitive info, and then demand payment to not leak it. - **They're persistent:** Once they find a working exploit, they'll keep using it until it's patched everywhere. - **They're adaptable:** The URL-encoding trick shows they're willing to evolve their methods to bypass defenses. - **They're targeting the US:** Many US-based companies rely on PeopleSoft for HR, finance, and supply chain management. That makes them prime targets. ### How to Protect Yourself First, patch CVE-2026-35273 immediately if you haven't already. Oracle released a fix, and applying it is the single most important step. But don't stop there. - **Update your WAF rules:** Work with your security vendor to ensure your WAF can detect encoded attacks. This might mean enabling additional decoding or normalization features. - **Monitor for unusual activity:** Look for strange URL patterns or unexpected outbound traffic. Attackers often leave traces. - **Segment your network:** Don't let a compromised PeopleSoft server give attackers access to everything else. - **Consider antidetect browsers for testing:** Security teams sometimes use antidetect browsers to simulate attacker behavior without being blocked. It's a niche use case, but it can help you understand how your defenses hold up. > "The bad guys only need one way in. You need to close every door." — Robert Moore, Lead Antidetect Browser Specialist ### The Bigger Picture This isn't just about one gang or one vulnerability. It's a reminder that security is a moving target. Attackers are constantly finding new ways to bypass our defenses. WAFs are useful, but they're not foolproof. You need layered security: patching, monitoring, segmentation, and a healthy dose of paranoia. If you're responsible for securing Oracle PeopleSoft, take this seriously. ShinyHunters isn't going away, and they've just shown they can adapt. Stay vigilant, keep your systems updated, and never assume you're safe. For more insights on digital privacy and security, keep following our blog.