{"id":244587,"date":"2026-09-29T01:21:36","date_gmt":"2026-09-29T06:21:36","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/09\/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks"},"modified":"2026-09-29T01:21:36","modified_gmt":"2026-09-29T06:21:36","slug":"shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/09\/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks","title":{"rendered":"ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks.jpg\"><\/a><\/p>\n<p>The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026\u201335273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.<\/p>\n<p>Google\u2019s Mandiant and Threat Intelligence Group (GTIG) say this new technique has allowed the threat actor to once again target PeopleSoft servers that had not applied security updates and instead blocked access to the vulnerable PSEMHUB endpoint using a WAF.<\/p>\n<p>On June 10, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks\/\" target=\"_blank\" rel=\"nofollow noopener\">BleepingComputer first reported<\/a> that the ShinyHunters extortion gang was targeting Oracle PeopleSoft servers using a zero-day vulnerability, allowing them to steal data from 100 organizations.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026\u201335273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. Google\u2019s Mandiant and Threat Intelligence Group (GTIG) say this new technique has allowed the threat actor to once again [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1492],"tags":[],"class_list":["post-244587","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244587","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=244587"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244587\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=244587"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=244587"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=244587"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}