Skip to content

Topic

Web application firewall evasion

Techniques attackers use to get malicious requests past web application firewalls and reverse-proxy filters, such as encoding tricks that exploit differences in how filters and applications parse input.

Current clusters

security5 publishers

ShinyHunters slips past PeopleSoft firewall rules by encoding one character

ShinyHunters is again mass-exploiting Oracle PeopleSoft flaw CVE-2026-35273, defeating firewall rules by URL-encoding a single character. Anyone who filtered the endpoint instead of applying Oracle's June 10 patch should assume exposure.

Perspective Coverage

5 publishers
Builder
Builder 31%
Operator
Operator 57%
Investor
Investor 12%

Reality

Evidence78
Adoption
Insufficient
Hype gap+10
Incentives40
Confidence75