ShinyHunters Oracle PeopleSoft attack concept showing WAF bypass and enterprise data threat

ShinyHunters Oracle PeopleSoft Attack: Critical WAF Bypass Alert

ShinyHunters Oracle PeopleSoft Attack: Critical WAF Bypass Exposes Enterprises

The ShinyHunters Oracle PeopleSoft attack campaign has escalated dramatically, with the notorious extortion gang deploying a sophisticated URL-encoding technique to circumvent web application firewall protections. Australian organisations running Oracle PeopleSoft systems face immediate risk as threat actors exploit the critical CVE-2026-35273 vulnerability through this newly discovered bypass method. Security teams must act swiftly to prevent data theft and extortion attempts targeting their enterprise resource planning infrastructure.

“The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.”

— Source: BleepingComputer

What Happened: ShinyHunters Resumes Widespread Exploitation

The ShinyHunters cybercriminal group, responsible for numerous high-profile data breaches since 2020, has discovered a method to bypass security controls protecting vulnerable Oracle PeopleSoft installations. This development renders previously effective web application firewall (WAF) rules ineffective against the ongoing attack campaign.

Initially, organisations deployed WAF rules to block exploitation attempts targeting CVE-2026-35273. These protective measures provided temporary relief from the attack wave. However, ShinyHunters’ latest technique has invalidated these defences, exposing thousands of enterprise systems worldwide.

The threat actors are specifically targeting organisations that believed themselves protected, catching security teams off-guard. This attack represents a significant escalation in the group’s capabilities and demonstrates their persistence in exploiting high-value enterprise targets.

How Does the WAF Bypass Technique Work?

The bypass method leverages URL encoding to obfuscate malicious payloads, effectively evading pattern-matching rules implemented in web application firewalls. By encoding specific characters in the attack string, the payload appears benign to security filters whilst remaining executable by the target PeopleSoft application.

Technical Breakdown of the Attack Chain

The attack exploits the following sequence:

  1. Initial reconnaissance — Attackers identify internet-facing PeopleSoft instances through automated scanning
  2. Payload encoding — Malicious requests are URL-encoded to bypass WAF signature detection
  3. CVE-2026-35273 exploitation — The encoded payload triggers the underlying vulnerability
  4. Data exfiltration — Sensitive enterprise data is harvested for extortion purposes

Traditional WAF rules match specific character patterns associated with the exploit. By encoding these characters (for example, converting spaces to %20 or special characters to their hexadecimal equivalents), the attack string no longer matches detection signatures.

Why Standard WAF Rules Failed

Many WAF configurations inspect requests before URL decoding occurs, or they fail to perform recursive decoding on nested encoded strings. ShinyHunters has exploited this architectural weakness to slip past defences that would otherwise block the CVE-2026-35273 exploit.

Business Impact of the Oracle PeopleSoft Vulnerability

Oracle PeopleSoft serves as critical infrastructure for human resources, financial management, and supply chain operations across thousands of enterprises globally. A successful breach can expose:

  • Employee personal identifiable information (PII) including tax file numbers and banking details
  • Payroll records and salary information
  • Financial transactions and corporate accounting data
  • Supply chain contracts and vendor information
  • Student records (for educational institutions using Campus Solutions)

ShinyHunters has established a pattern of stealing data and subsequently demanding ransom payments to prevent public disclosure. Organisations that fail to pay often see their data published on dark web marketplaces or public leak sites.

The financial consequences extend beyond ransom demands. Australian businesses face potential penalties under the Privacy Act, reputational damage, operational disruption, and costly incident response efforts.

Actionable Recommendations for Security Teams

Organisations running Oracle PeopleSoft must implement immediate protective measures to defend against this ShinyHunters Oracle PeopleSoft attack campaign.

Immediate Actions (Within 24-48 Hours)

  • Apply Oracle’s official patch for CVE-2026-35273 immediately — this remains the only definitive fix
  • Update WAF rules to decode URLs before pattern matching and implement recursive decoding
  • Enable enhanced logging on PeopleSoft web servers to detect exploitation attempts
  • Restrict internet-facing access to PeopleSoft instances where possible
  • Implement IP-based access controls for administrative interfaces

Short-Term Hardening Measures

  • Deploy virtual patching through updated WAF signatures that account for encoding variations
  • Conduct emergency vulnerability scanning across all PeopleSoft environments
  • Review and restrict database account privileges used by PeopleSoft applications
  • Implement network segmentation to limit lateral movement opportunities

If your organisation lacks internal resources to address this threat, consider engaging vulnerability management services to rapidly assess and remediate your exposure.

Long-Term Security Improvements

  • Establish a regular patching cadence for Oracle products
  • Implement application-layer monitoring and anomaly detection
  • Conduct penetration testing specifically targeting encoding bypass techniques
  • Develop incident response playbooks for extortion scenarios

Frequently Asked Questions

What is the CVE-2026-35273 Oracle PeopleSoft vulnerability?

CVE-2026-35273 is a critical security flaw in Oracle PeopleSoft that allows remote attackers to compromise vulnerable systems. When exploited, threat actors can gain unauthorised access to sensitive enterprise data including HR records, financial information, and personally identifiable information. Oracle has released patches to address this vulnerability.

How can I protect my business from the ShinyHunters Oracle PeopleSoft attack?

The most effective protection is applying Oracle’s official security patch for CVE-2026-35273 immediately. Additionally, organisations should update their WAF configurations to perform URL decoding before pattern matching, restrict internet access to PeopleSoft systems, and implement enhanced monitoring for suspicious activity. If you require assistance, speak with our security team for expert guidance.

Who is ShinyHunters and why are they targeting PeopleSoft?

ShinyHunters is a cybercriminal extortion gang active since 2020, responsible for breaches affecting organisations including Microsoft, Tokopedia, and AT&T. They target systems like PeopleSoft because these platforms contain high-value data — employee records, financial data, and personal information — that commands significant ransom payments or sells profitably on dark web markets.

Key Takeaways

  • ShinyHunters has bypassed WAF protections using URL-encoding techniques to exploit CVE-2026-35273
  • Organisations relying solely on WAF rules for protection are now vulnerable
  • Patching remains the only definitive fix — apply Oracle’s security update immediately
  • WAF configurations must be updated to perform pre-decoding analysis
  • PeopleSoft systems contain highly sensitive data attractive to extortion gangs
  • Australian organisations face regulatory, financial, and reputational risks from successful breaches

Conclusion: Act Now to Prevent Exploitation

The ShinyHunters Oracle PeopleSoft attack campaign demonstrates how quickly threat actors adapt to circumvent defensive measures. Organisations cannot afford complacency — the window for proactive protection narrows daily as attackers refine their techniques and expand their target lists.

Security teams must prioritise patching vulnerable PeopleSoft installations whilst simultaneously hardening WAF configurations against encoding bypass techniques. Those who delay risk joining the growing list of ShinyHunters victims facing data theft, extortion demands, and regulatory scrutiny.

OziTechs continues monitoring this evolving threat and advises all Australian organisations running Oracle PeopleSoft to treat this as a critical security incident requiring immediate executive attention and resource allocation.

Tagged , , , , , .