Attackers Are Now Hiding Behind the Flaws We Didn't Patch

Photo: BleepingComputer

Article

Attackers Are Now Hiding Behind the Flaws We Didn't Patch

JaysuryaOctober 1, 20265 min read

The recent cases logged by BleepingComputer share one thread: attackers are no longer waiting for defenders to miss a patch. They are finding ways around the mitigations that organizations actually deployed, exploiting not just the gap between disclosure and fix, but the gap between fix and effective fix. ShinyHunters bypassed a web application firewall guarding Oracle PeopleSoft, the Clop gang's own leak site fell to an unpatched content management system flaw, and CISA is warning that an authentication bypass in WSO2 products is being exploited in the wild. Each incident turns on a control that was supposed to be sufficient and was not, and each lands squarely on US enterprises and the consumers whose data sits behind those controls.

The Bypass Is the Story

The Oracle PeopleSoft case is the clearest illustration. ShinyHunters is using a URL-encoding trick to slip past web application firewall rules that were meant to mitigate CVE-2026-35273, according to BleepingComputer. That matters more than the underlying vulnerability. A WAF rule is often the fastest mitigation available when a patch cannot be deployed immediately across a sprawling enterprise system, and it is exactly the kind of compensating control that security teams rely on during the window between disclosure and full remediation. When attackers can encode their way around those rules, the mitigation window effectively closes. The flaw remains exploitable on vulnerable servers, and the attackers have resumed widespread exploitation, as BleepingComputer reported. For US technology companies running PeopleSoft in finance, HR, and campus environments, the practical lesson is that a WAF is a speed bump, not a wall, and that temporary mitigations cannot be treated as permanent posture.

Mitigations Assume Attackers Stop Trying

The WSO2 warning from CISA points at the same underlying assumption. The agency is flagging a critical authentication bypass, tracked as CVE-2026-5430, affecting multiple products from the enterprise software provider. An authentication bypass is particularly consequential because it undermines the gate itself rather than a door behind it. Organizations that deployed the product with the expectation that authentication would hold are exposed, and CISA's warning that the flaw is being exploited in attacks means the theoretical risk has already materialized. The material does not specify the scale or the victims, and it would be wrong to imply more than that. What is clear is the pattern: a control that many security architectures treat as foundational is being circumvented, and the warning arrives after exploitation is underway. For US enterprises that standardize on a single identity or integration vendor, the concentration risk is the point. One authentication bypass at a widely deployed provider ripples across every customer that trusted it.

Even the Attackers Are Exposed

The Clop ransomware gang's leak site compromise is the most telling detail in the set, because it shows the same dynamic applying to the attackers themselves. According to BleepingComputer, Clop moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw, which BleepingComputer has learned is an unauthenticated path traversal vulnerability. ShinyHunters, the extortion gang, carried out the hack. The irony is useful analytically rather than merely entertaining. The people who make a business of exploiting unpatched systems left one of their own unpatched, and a rival group walked through it. That is not just a comeuppance story. It is evidence that the unpatched-system problem is systemic and indifferent to intent. The same failure mode that exposes a hospital, a university, or a payroll provider also exposed a criminal operation. The difference is that the criminals had no compliance officer, no CISA advisory, and no vendor relationship to manage, and they still failed. That should temper any confidence that a mature organization is immune by virtue of maturity alone.

What This Means for US Companies

The through-line has a specific US shape. American enterprises run deep stacks of enterprise software, and the products named here, WSO2, Oracle PeopleSoft, and Adobe Commerce (referenced in the CISA warning alongside the WSO2 flaw), sit in the operational core of large organizations. Authentication bypasses and WAF evasions are not exotic; they are the mechanics by which a single overlooked system becomes a breach that reaches customer records, employee data, and financial workflows. The consumer consequence is indirect but real. When a PeopleSoft instance or an authentication layer is compromised, the downstream effects show up as credential stuffing waves, fraudulent account activity, and notification letters. US consumers rarely see the vendor name in those letters. They see the brand of the company that trusted the vendor, which is why the reputational and regulatory exposure ultimately rests with the enterprise, not the software provider.

The Economics of Unfinished Work

The pattern also reframes where security spending should go. Finding new vulnerabilities is a well-funded, well-tooled activity. Finishing the remediation of known ones is not. The ShinyHunters campaigns show that a determined attacker will invest effort in defeating a mitigation rather than waiting for a new flaw, and the Clop case shows that leaving a known flaw unpatched is a liability regardless of who you are. For US technology companies, the implication is that patch velocity and mitigation verification deserve the same rigor as detection. A WAF rule that has never been tested against encoding variations is an assumption, not a control. An authentication layer that has never been reviewed for bypass conditions is a promise, not a guarantee. The material here does not quantify how many organizations are exposed, and it would be irresponsible to guess. But the direction of travel is unambiguous: attackers are targeting the seam between what defenders deployed and what defenders verified.

What to Watch

Three things bear watching, all grounded in what has been reported. First, whether CISA's WSO2 warning is followed by further advisories naming additional affected products, since the current notice covers multiple products but not a full inventory. Second, whether ShinyHunters' URL-encoding technique against Oracle PeopleSoft WAF rules becomes a template that other groups copy, which would turn a single campaign into a broader class of evasion. Third, whether Clop's move to a new Tor address after the Grav CMS compromise produces any disruption to its extortion operations, or whether the group simply relocates and continues. The common thread to watch across all three is mitigation durability. The question for US enterprises between now and the end of the year is not whether they have patched, but whether they have confirmed that what they deployed actually holds when someone tries to go around it.

More on this beat: Cybersecurity on TechManNews.

#cyber attacks#vulnerability exploitation#WAF bypass#enterprise software#patch management#extortion gangs

Newsletter

Get Tech News in Your Inbox

The latest AI, gadgets, software and startup stories from TechManNews, delivered every morning - free.