Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally.

The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution.

The vulnerability was first exploited as a zero-day

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

OpenAI loses trademark dispute at EU court

OpenAI loses trademark dispute at EU court Source: Hacker News

I built Ponytrail, a local audit trail for AI coding-agent edits

I built Ponytrail, a local audit trail for AI coding-agent edits Source: Hacker News

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers WordPress has fixed a critical flaw in its core software that lets an attacker with no