{"ok":true,"trend":{"id":48234,"platform":"mastodon","region":"global","key":"🤖 oracle peoplesoft cve-2026-35273 (cvss 9.8, unauthenticated rce) is being mass-exploited again by shinyhunters. attack","title":"🤖 Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8, unauthenticated RCE) is being mass-exploited again by ShinyHunters. Attack","url":"https://infosec.exchange/@cloud/117340277525000820","first_seen":"2026-09-27T01:28:36.940071Z","last_seen":"2026-09-27T01:28:36.940071Z","last_rank":7,"peak_rank":7,"last_volume":2,"peak_volume":2,"seen_count":1,"score":0.9371875,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"Attackers are mass-exploiting a critical Oracle PeopleSoft vulnerability, CVE-2026-35273, rated CVSS 9.8 as an unauthenticated remote code execution flaw. The ShinyHunters group is reportedly using URL-encoding tricks to bypass WAF rules before deploying web shells. Google has warned of global targeting across multiple sectors, and renewed exploitation waves are drawing fresh attention from security teams.","why":"Renewed mass exploitation of a critical, remotely exploitable Oracle flaw is prompting urgent warnings and patching efforts worldwide.","tone":"negative","entities":["Oracle","PeopleSoft","ShinyHunters","Google"],"summarized_at":"2026-09-27T01:29:57.640556Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","generic":0.03,"instance":"mastodon.social","tag_uses":613},"nw":0.53,"promo":0.03,"kind":"news_event","importance":1.81,"hidden":false,"hide_reason":null,"judged_at":"2026-09-27T01:28:37.587799Z","title_en":"Oracle PeopleSoft flaw mass-exploited by ShinyHunters","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-09-27T01:28:36.940071Z","rank":7,"volume":2}],"posts":[{"platform":"mastodon","url":"https://infosec.exchange/@cloud/117340277525000820","author":"cloud@infosec.exchange","title":null,"snippet":"🤖 Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8, unauthenticated RCE) is being mass-exploited again by ShinyHunters. Attackers use URL-encoding tricks to bypass WAF rules meant to block the flaw, then drop web shells. Google warns of global multi-sector targeting. 🔗 https://…","posted_at":"2026-09-27T00:55:43Z","likes":2}],"elsewhere":[],"window":"7d"}}