ShinyHunters Exploits Oracle PeopleSoft Flaw CVE-2026-35273 to Bypass WAFs

Élevé · BleepingComputer ·

Exploité

En bref

  • ShinyHunters is exploiting CVE-2026-35273 in Oracle PeopleSoft.
  • The attack uses URL encoding to evade WAF and firewall protections.
  • Vulnerable servers are being targeted widely, with extortion as the goal.
  • Administrators should patch and review exposure immediately.

ShinyHunters, a group known for extortion, has restarted attacks that leverage CVE-2026-35273 in Oracle PeopleSoft. The operators rely on a URL-encoding method to slip past web application firewalls and to circumvent firewall policies. That evasion lets them reach unpatched PeopleSoft instances even when perimeter defenses are in place.

Organizations running Oracle PeopleSoft are the primary targets, particularly any deployment exposed to untrusted networks. The activity is not isolated: exploitation is being observed across many environments, suggesting broad scanning and opportunistic targeting. Once access is achieved, the crew appears to pursue extortion.

The WAF bypass is significant because it weakens a common control that many teams depend on for virtual patching. Firewall rules alone may also fail when malicious requests are encoded. The fact that the gang has resumed this campaign indicates that earlier blocking efforts or mitigations have not fully closed the exposure.

With a high severity rating assigned to CVE-2026-35273, defenders should treat internet-facing PeopleSoft servers as urgent priorities. The combination of widespread exploitation and extortion raises the risk of operational disruption, data theft, and reputational harm.

Watch for renewed ShinyHunters activity, unusual encoded requests in web logs, and signs of post-exploitation extortion. Confirm whether PeopleSoft systems are patched, review WAF and firewall configurations, and be ready to isolate affected hosts quickly.

À faire maintenant

  1. Apply the vendor patch for CVE-2026-35273 to all Oracle PeopleSoft servers as the top priority; if patching is delayed, take affected systems offline or restrict access.
  2. Review WAF and firewall rules for URL-encoding evasion; test whether encoded payloads reach PeopleSoft endpoints and tighten normalization and inspection.
  3. Reduce internet exposure by placing PeopleSoft behind VPN, allowlisting, or zero-trust access controls until remediation is complete.
  4. Search web, application, and firewall logs for encoded requests, WAF bypass attempts, and unusual PeopleSoft activity tied to CVE-2026-35273.
  5. Hunt for signs of ShinyHunters intrusion and extortion, including new accounts, data staging, and outbound connections from PeopleSoft hosts.
  6. Enable enhanced monitoring and alerting for PeopleSoft servers, and validate that backups and incident response contacts are current.
  7. If compromise is suspected, isolate the server, preserve logs, and engage incident response before restoring service.

Références CVE

  • CVE-2026-35273

Source originale

BleepingComputer

Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.

← Toute la veille cyber