Security Feed
  1. Archives

Sep 26 2026 ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

Source

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. [...]

Posted by Lawrence Abrams on Sat 26 September 2026 in BleepingComputer.

Tags: Security.

Categories

  1. Ars Technica
  2. AWS Security
  3. BleepingComputer
  4. Brian Krebs
  5. Bruce Schneier
  6. GCP Security
  7. Google Project Zero
  8. The Daily Swig
  9. The Guardian
  10. The Register
  11. Threatpost

Tag cloud

  • Security
  • Uncategorized
  • Security, Identity, & Compliance
  • Security Blog
  • Biz & IT
  • Microsoft
  • AI
  • Security & Identity
  • Artificial Intelligence
  • Announcements
  • CryptoCurrency
  • google
  • Foundational (100)
  • Legal
  • privacy
  • A Little Sunshine
  • Apple
  • Advanced (300)
  • LLM
  • Intermediate (200)
  • squid
  • Hacking
  • Technical How-to
  • Mobile
  • vulnerabilities

Security Feed. Powered by Pelican and m.css. Code is available on GitLab.