Oct 2, 2026 · 37 min · 8 segments
In this episode, we break down four security stories: - A ShinyHunters PeopleSoft WAF bypass that hinges on one URL-encoded character - The arrest of an alleged ShinyHunters leader days before the…
In summary, the, uh, ShinyHunters, they're back, they're exploiting the same critical PeopleSoft vulnerability it targeted earlier this year.
But this time it's get- it's getting around WAF rules that organizations put in place as a mitigation.
It's URL encode a single letter in the vulnerable path, and some WAFs no longer recognize what they're supposed to block.
Yeah, I mean, for the, for the most part it's, uh, CIS admins kinda letting the, the ball down and, uh, it's, it's entirely, uh, up to them to make sure that when they implement WAF rules, they kind of understand what the rou- the WAF rule is supposed to block.
And, uh, if they're only, if they're only blocking literal strings, then they really need to step back and look at, uh, history and realizing why that's a really bad way of doing stuff.
And that they should probably, you know, in, do some form of interpretation on their string, uh, to make sure that the true intent of the string is being blocked.
Uh, because percent 50 is, uh, not that hard and, uh, to, to, to, to write into your browser.
And, uh, if that is the only thing stopping a person from exploiting a very critical all the way to RCE, uh, vulnerability, then, uh, I think you probably should take a few more seconds to implement, uh, a slightly better rule, uh, for, for your WAF.
I hope it was a little bit more complicated because I think this is, uh, we'll get to this a little bit later, but this was tied into their previous things of, of compromising the, uh, FBI's, you know, jobs.gov, whatever instance that-
In summary, the, uh, ShinyHunters, they're back, they're exploiting the same critical PeopleSoft vulnerability it targeted earlier this year.
But this time it's get- it's getting around WAF rules that organizations put in place as a mitigation.
It's URL encode a single letter in the vulnerable path, and some WAFs no longer recognize what they're supposed to block.
Yeah, I mean, for the, for the most part it's, uh, CIS admins kinda letting the, the ball down and, uh, it's, it's entirely, uh, up to them to make sure that when they implement WAF rules, they kind of understand what the rou- the WAF rule is supposed to block.
And, uh, if they're only, if they're only blocking literal strings, then they really need to step back and look at, uh, history and realizing why that's a really bad way of doing stuff.
And that they should probably, you know, in, do some form of interpretation on their string, uh, to make sure that the true intent of the string is being blocked.
Uh, because percent 50 is, uh, not that hard and, uh, to, to, to, to write into your browser.
And, uh, if that is the only thing stopping a person from exploiting a very critical all the way to RCE, uh, vulnerability, then, uh, I think you probably should take a few more seconds to implement, uh, a slightly better rule, uh, for, for your WAF.
I hope it was a little bit more complicated because I think this is, uh, we'll get to this a little bit later, but this was tied into their previous things of, of compromising the, uh, FBI's, you know, jobs.gov, whatever instance that-
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.