ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
A WAF rule that blocks /PSEMHUB/ does nothing if the attacker asks for /%50SEMHUB/ instead. That’s the whole trick ShinyHunters is using against Oracle PeopleSoft (CVE-2026-35273, patched back in June): Mandiant says many WAFs and reverse proxies compare the literal request path before decoding it. Web shells landed on dozens of systems worldwide. Worth checking whether your own proxy normalises before it matches.