ShinyHunters Targets Oracle PeopleSoft Customers Through Critical Zero-day
Oracle has issued a security alert to customers about a critical vulnerability affecting PeopleSoft environments after the notorious threat actor ShinyHunters claimed it used a previously unknown flaw to compromise over 100 entities.
The vulnerability CVE-2026-35273 is in Oracle PeopleSoft PeopleTools, and has a CVSS score of 9.8/10. “Oracle PeopleSoft Enterprise Applications customers may also be affected by this vulnerability. This vulnerability is remotely exploitable without authentication. If successfully exploited, this vulnerability may result in remote code execution,” the alert read.
ShinyHunters said they exploited a zero-day vulnerability in Oracle PeopleSoft systems to gain access to customer environments and steal sensitive data.
Oracle released guidance for customers, while stating there is no evidence of a compromise of Oracle Cloud infrastructure.
According to researchers and response teams, the alleged attacks were aimed at customer-managed PeopleSoft installations, and not Oracle Cloud services. It has encouraged companies using impacted applications to conduct configuration...
Copyright of this story solely belongs to informationsecuritybuzz.com. To see the full text click HERE