ShinyHunters is mass-exploiting Oracle PeopleSoft again, and this time one URL-encoded character walks straight past the WAF rules organizations deployed instead of patching. Inside the attack chain, the new SIDEEYE backdoor, the sectors being hit, and the hunt-and-patch plan CISOs need this week.