ShinyHunters bypasses WAF blocks in renewed Oracle PeopleSoft attacks
Google's Mandiant and Threat Intelligence Group report that the ShinyHunters extortion gang, tracked as UNC6240, has modified its exploit for the Oracle PeopleSoft flaw CVE-2026-35273 to bypass web application firewall protections. By URL-encoding characters in the vulnerable /PSEMHUB/ endpoint path, such as '%50' for the letter 'P', attackers can slip past WAF rules that only check the literal, unencoded path while Oracle WebLogic still decodes and routes the request to the vulnerable endpoint.