The cybercriminal group ShinyHunters has resumed its attacks by exploiting a vulnerability in Oracle PeopleSoft, specifically targeting CVE-2026-35273. This attack vector involves using URL-encoding techniques to bypass Web Application Firewalls, enabling the attackers to gain unauthorized access to sensitive data. The vulnerability in question affects organizations using Oracle PeopleSoft, a popular enterprise application suite, putting a wide range of industries at risk.

The bypass method employed by ShinyHunters is significant because it allows the group to circumvent security measures that many companies rely on to protect their web applications. This tactic underscores the evolving nature of cyber threats and highlights the importance of maintaining up-to-date security measures. Impacted organizations could face data breaches that compromise personal and financial information, leading to potential financial losses and reputational damage.

To mitigate the risk posed by this vulnerability, organizations using Oracle PeopleSoft should immediately apply any available patches from Oracle. Regular security audits and penetration testing can help identify weaknesses in existing defenses. Additionally, reviewing and upgrading Web Application Firewall configurations will strengthen defenses against similar bypass techniques in the future.