RC RANDOM CHAOS

Attackers Bypass WAFs to Exploit Oracle Flaw in Global Campaign

· via The Hacker News

Original source

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

The Hacker News →

Google’s Mandiant unit warns of renewed attacks exploiting CVE-2026-35273 in Oracle PeopleSoft, a critical flaw allowing unauthenticated remote code execution. The threat actor, UNC6240, has modified its exploit to bypass web application firewall (WAF) rules by URL-encoding a single character in the request path. Targets span multiple sectors, including higher education, healthcare, and government, with attackers deploying web shells on dozens of systems. The attack chain involves Java deserialization abuse, fileless command execution, and the deployment of a C++ backdoor (SIDEEYE) for credential theft and system control.

Read the full article

Continue reading at The Hacker News →

This is an AI-generated summary. Read the original for the full story.