Cybersecurity
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
ShinyHunters-linked attackers exploit CVE-2026-35273 in Oracle PeopleSoft, bypassing WAF rules to deploy web shells on dozens of systems.
Summary
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedCoverage Context
More from Cybersecurity
Continue reading recent Cybersecurity coverage
- GitHub Actions re-enabled with Mini Shai-Hulud payload still activeContinue reading
- OpenAI's AI agents accidentally uploaded user-provided images to third-party sitesContinue reading
- New x47.c Windows Botnet Weaponizes xAI Grok, AI API DrainingContinue reading
- OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior DisclosureContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow