TTO-2026-0926-170 · September 26, 2026 Threat ActorFollow-Up

ShinyHunters Used WAF Bypass to Exploit Oracle PeopleSoft in FBI Attack — Updates TTO-2026-0922-151

oracle.comShinyHuntersWAF bypass technique confirmedOracle PeopleSoft zero-day attack vectorFBI breach claim — technical detail confirmedUpdates TTO-2026-0922-151

Summary

Security researchers have confirmed the technical attack vector used by ShinyHunters in the Oracle PeopleSoft zero-day attack documented as an unverified claim in TTO-2026-0922-151. ShinyHunters used a web application firewall bypass technique to deliver their PeopleSoft exploit payload past perimeter security controls without triggering WAF inspection rules. The WAF bypass allowed the group to reach the underlying PeopleSoft vulnerability directly, circumventing the primary network-layer defense organizations commonly rely on to compensate for unpatched enterprise application vulnerabilities. The FBI breach claim itself remains unconfirmed by the FBI or Department of Justice, but the technical attack pathway against PeopleSoft has been independently validated.

Timeline

DateEvent
Sep 21-22, 2026ShinyHunters publicly claims FBI network breach via Oracle PeopleSoft zero-day; TTO-2026-0922-151 published as unverified
Sep 25-26, 2026Security researchers confirm WAF bypass technique used to deliver PeopleSoft exploit; BleepingComputer reports technical detail confirmation
Sep 26, 2026FBI breach claim still unconfirmed by FBI or DOJ; Oracle has not confirmed PeopleSoft zero-day CVE; TTO-2026-0926-170 published

What Changed

TTO-2026-0922-151 documented ShinyHunters’ claim that it had breached FBI infrastructure via a zero-day vulnerability in Oracle PeopleSoft, noting that neither the FBI, DOJ, nor Oracle had confirmed the claim. That assessment remains accurate for the breach claim itself.

What has now been confirmed is the technical mechanism: a WAF bypass technique that caused the WAF to fail to inspect the malicious request payload. WAF bypasses exploit inconsistencies between how a WAF parses request content and how the target application parses the same content — encoding, fragmenting, or formatting a payload in a way the WAF does not recognize as malicious while the application processes it correctly. PeopleSoft environments in government agencies are commonly placed behind WAF solutions as a compensating control for unpatched vulnerabilities. The WAF bypass confirmation means organizations relying on perimeter WAF controls to protect unpatched PeopleSoft instances should treat those controls as insufficient against ShinyHunters’ current tooling.

Domain Intelligence

oracle.com — 62.46

Score unchanged from TTO-2026-0922-151. oracle.com scores in the low-trust range at 62.46. Oracle is the vendor of PeopleSoft, the platform alleged to contain the zero-day exploited in this attack. Oracle has not confirmed a PeopleSoft zero-day CVE as of this publication.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 26, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026