Oracle warns customers of critical PeopleSoft attack after hundreds of servers hacked by apparent ShinyHunters data…
- ShinyHunters likely behind the CVE-2026-35273 attack on Oracle's PeopleSoft
- Versions 8.61 and 8.62 affected, users urged to take "immediate action"
- Google's Mandiant informed over 100 organizations
Oracle PeopleSoft servers, used by universities, businesses and public sector organizations, are being targeted in a new attack by extortion group ShinyHunters, researchers have revealed.
The attackers claim to have compromised more than 100 organizations, and exfiltrated data from around 300 PeopleSoft instances, by exploiting a vulnerability tracked as CVE-2026-35273.
Victims have reportedly received demands signed by ShinyHunters threatening to release stolen data, unless a ransom is paid, with another researcher adding that it could be "a group impersonating them," implying the group has not yet taken accountability for the attacks.
Oracle PeopleSoft customers vulnerable to attacks and ransom demands
"This vulnerability is remotely exploitable without authentication," Oracle addedin a June 10 security advisory. "If successfully exploited, this vulnerability may result in remote...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE