Skip to content
Tech News
← Back to articles

ShinyHunters bypasses WAF blocks in renewed Oracle PeopleSoft attacks

read original more articles
GoKawiil Brief

Google's Mandiant and Threat Intelligence Group report that the ShinyHunters extortion gang, tracked as UNC6240, has modified its exploit for the Oracle PeopleSoft flaw CVE-2026-35273 to bypass web application firewall protections. By URL-encoding characters in the vulnerable /PSEMHUB/ endpoint path, such as '%50' for the letter 'P', attackers can slip past WAF rules that only check the literal, unencoded path while Oracle WebLogic still decodes and routes the request to the vulnerable endpoint.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

This suggests organizations that relied on WAF rules as a stopgap—rather than applying Oracle's patch or disabling the Environment Management Hub—may still be exposed despite believing themselves protected. It highlights a broader weakness in mitigation strategies that block literal paths rather than accounting for encoding variations that backend servers will decode and process anyway.

Key Takeaways

Source: bleepingcomputer.com, 2026-09-26

Published there as: “ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.