The ShinyHunters extortion group has reignited its campaign against Oracle PeopleSoft servers, using a straightforward evasion tactic to circumvent web application firewall (WAF) rules that many organizations deployed as an interim fix for a critical vulnerability.

The attacks target CVE-2026-35273, a high-severity flaw that allows unauthenticated remote command execution. In the wake of its disclosure, numerous security teams instituted WAF signatures to block exploit patterns while preparing to apply the official Oracle patch. ShinyHunters has now found a way around these initial defenses.

The group’s method involves URL-encoding its attack payloads. By sending malicious strings to PeopleSoft endpoints in an encoded format, the threat actors can often slip past WAF inspection. This technique is effective if the WAF is not configured to decode and normalize such traffic before applying its security rules, allowing the malicious request to reach the vulnerable application undetected.

This development demonstrates a common attacker playbook and highlights a key weakness in relying solely on signature-based mitigations. As noted in industry reports, such rules can become a fragile shield. "Attackers only need to find one simple obfuscation technique to bypass static rules," the analysis points out, underscoring that layered defenses are temporary stops, not permanent solutions.

For organizations using PeopleSoft for critical HR and financial data, the threat is direct. ShinyHunters specializes in data theft and extortion, making these systems high-value targets.

A two-tiered defense is required immediately:

1. Primary Action: Patch Immediately The definitive solution is to apply Oracle’s Critical Patch Update for CVE-2026-35273. This eliminates the root vulnerability and is the only lasting remedy.

2. Interim Measure: Harden WAF Configuration While patching is underway, security teams must audit and correct their WAF settings. The critical step is ensuring the WAF is configured to fully normalize and decode all incoming traffic—including URL-encoded and double-encoded payloads—before inspecting it with detection signatures. Without this preprocessing step, any WAF rule remains vulnerable to simple bypass tricks.

This incident serves as a practical lesson in defense-in-depth. A single protective layer, however well-intentioned, creates a point of failure. Effective security requires combining timely patching with properly configured, layered defenses to counter evolving threats.


勒索軟件組織 ShinyHunters 再度針對 Oracle PeopleSoft 伺服器發動攻擊,採用一個直接的規避手法,以繞過許多組織為應對嚴重漏洞而部署的網絡應用程式防火牆(WAF)規則。

這次攻擊針對的是 CVE-2026-35273,一個允許未經身份驗證遠端執行命令的高嚴重性漏洞。在漏洞被披露後,眾多安全團隊制定了 WAF 簽名規則以阻止攻擊模式,同時準備套用官方的 Oracle 修補程式。ShinyHunters 現在找到了繞過這些初步防禦的方法。

該組織的手法是對其攻擊載荷進行 URL 編碼。透過以編碼格式向 PeopleSoft 端點傳送惡意字串,威脅行為者往往能避開 WAF 的檢查。若 WAF 未設定為在套用安全規則前對此類流量進行解碼及標準化,此技術便能生效,使惡意請求能夠未被偵測地到達有漏洞的應用程式。

這次發展揭示了攻擊者常見的策略,並突顯了單純依賴基於簽名的緩解措施的一個關鍵弱點。正如業界報告所指出,此類規則可能變得不堪一擊。分析強調:「攻擊者只需要找到一種簡單的混淆技巧就能繞過靜態規則」,並指出多層防禦只是臨時阻擋,並非長久之計。

對於使用 PeopleSoft 處理關鍵人力資源及財務數據的組織而言,威脅是直接的。ShinyHunters 專精於數據竊取與勒索,這使這些系統成為高價值目標。

組織必須立即採取兩層防禦措施:

1. 首要行動:立即修補 根本解決方案是套用針對 CVE-2026-35273 的 Oracle 關鍵修補程式更新。這能消除根本漏洞,也是唯一長久的補救方法。

2. 過渡措施:強化 WAF 設定 在進行修補的同時,安全團隊必須審核並修正其 WAF 設定。關鍵步驟是確保 WAF 被設定為在套用偵測簽名規則前,能完全標準化並解碼所有傳入流量——包括 URL 編碼及雙重編碼的載荷。若無此預處理步驟,任何 WAF 規則都容易受到簡單繞過技巧的攻擊。

此事件是一次關於縱深防禦的實務教訓。單一防護層,無論其意圖多麼良好,都會創造一個失敗點。有效的安全措施需要結合及時的修補與配置恰當、層次分明的防禦,以應對不斷演變的威脅。

新聞來源 / Original News Source