Awareness Lessons
2 weeks ago
WAF Bypass Exposes Unpatched PeopleSoft Servers to ShinyHunters
ShinyHunters exploited CVE-2026-35273 in Oracle PeopleSoft by using URL-encoding tricks to bypass WAF protections, reaching vulnerable endpoints that security teams believed were already shielded. This attack illustrates a critical and common misconception: WAFs are a compensating control, not a substitute for patching. Organizations that delayed applying the patch while relying solely on WAF rules created a false sense of security. Once the WAF was bypassed, attackers deployed web shells and exfiltrated data with minimal friction, demonstrating how a single unmitigated vulnerability can lead to full compromise.
Tactical Insight
Immediate actions
- Apply Oracle's official patch for CVE-2026-35273 on all PeopleSoft instances immediately, regardless of WAF coverage.
- Audit all internet-facing PeopleSoft servers for signs of web shell deployment or unauthorized executables.
- Review and update WAF rule sets to detect URL-encoding and other obfuscation bypass techniques.
Long-term improvements
- Establish a formal patch management policy with defined SLAs for critical CVEs on internet-facing systems (e.g., patch within 24–72 hours).
- Never treat WAFs, IDS/IPS, or other perimeter controls as a permanent substitute for vulnerability remediation.
- Implement network segmentation to isolate PeopleSoft and other ERP systems from the broader corporate network.
Detection measures
- Deploy file integrity monitoring on PeopleSoft servers to detect unauthorized web shell creation or binary drops.
- Enable detailed logging of all requests to sensitive endpoints (e.g., PSEMHUB) and alert on anomalous URL encoding patterns.
- Conduct regular authenticated vulnerability scans and penetration tests against ERP systems to validate patch status and WAF effectiveness.