Summary
Security researchers have confirmed the technical attack vector used by ShinyHunters in the Oracle PeopleSoft zero-day attack documented as an unverified claim in TTO-2026-0922-151. ShinyHunters used a web application firewall bypass technique to deliver their PeopleSoft exploit payload past perimeter security controls without triggering WAF inspection rules. The WAF bypass allowed the group to reach the underlying PeopleSoft vulnerability directly, circumventing the primary network-layer defense organizations commonly rely on to compensate for unpatched enterprise application vulnerabilities. The FBI breach claim itself remains unconfirmed by the FBI or Department of Justice, but the technical attack pathway against PeopleSoft has been independently validated.
Timeline
| Date | Event |
|---|---|
| Sep 21-22, 2026 | ShinyHunters publicly claims FBI network breach via Oracle PeopleSoft zero-day; TTO-2026-0922-151 published as unverified |
| Sep 25-26, 2026 | Security researchers confirm WAF bypass technique used to deliver PeopleSoft exploit; BleepingComputer reports technical detail confirmation |
| Sep 26, 2026 | FBI breach claim still unconfirmed by FBI or DOJ; Oracle has not confirmed PeopleSoft zero-day CVE; TTO-2026-0926-170 published |
What Changed
TTO-2026-0922-151 documented ShinyHunters’ claim that it had breached FBI infrastructure via a zero-day vulnerability in Oracle PeopleSoft, noting that neither the FBI, DOJ, nor Oracle had confirmed the claim. That assessment remains accurate for the breach claim itself.
What has now been confirmed is the technical mechanism: a WAF bypass technique that caused the WAF to fail to inspect the malicious request payload. WAF bypasses exploit inconsistencies between how a WAF parses request content and how the target application parses the same content — encoding, fragmenting, or formatting a payload in a way the WAF does not recognize as malicious while the application processes it correctly. PeopleSoft environments in government agencies are commonly placed behind WAF solutions as a compensating control for unpatched vulnerabilities. The WAF bypass confirmation means organizations relying on perimeter WAF controls to protect unpatched PeopleSoft instances should treat those controls as insufficient against ShinyHunters’ current tooling.
Domain Intelligence
oracle.com — 62.46
Score unchanged from TTO-2026-0922-151. oracle.com scores in the low-trust range at 62.46. Oracle is the vendor of PeopleSoft, the platform alleged to contain the zero-day exploited in this attack. Oracle has not confirmed a PeopleSoft zero-day CVE as of this publication.
The Trust Observatory · thetrustobservatory.com · September 26, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026