• Homepage
  • News
  • eSports
  • PC
  • Playstation
  • Xbox
  • Nintendo
  • Reviews
  • Cosplay
What's Hot

watchOS 27: Everything we know about the new features landing on your Apple Watch

June 11, 2026

Bluesky launches group chats, as company shifts focus to community features

June 11, 2026

Anthropic is spending $150M to embed 1,000 AI fellows inside nonprofits. No degree required.

June 11, 2026
Facebook Twitter Instagram
  • Contact
  • Terms & Conditions
  • Privacy Policy
Facebook Twitter Instagram
Gaming MasterGaming Master
Subscribe
  • Homepage
  • News
  • eSports
  • PC
  • Playstation
  • Xbox
  • Nintendo
  • Reviews
  • Cosplay
Gaming MasterGaming Master
Home»Uncategorized»Oracle warns of security bug that hackers abused to breach 100+ companies
Uncategorized

Oracle warns of security bug that hackers abused to breach 100+ companies

By June 11, 2026No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


Oracle warned its corporate customers that there is a critical-rated vulnerability in its PeopleSoft software, which is used by large companies to manage payroll and human resources, a day after a cybercrime group took credit for abusing the flaw as part of a mass-hacking campaign.

The company published the security advisory on Thursday after the hacking group ShinyHunters claimed to have breached more than 100 organizations that use PeopleSoft servers.

Mandiant, the Google-owned security unit that investigates cyberattacks, warned in a blog post that the new Oracle flaw is the same bug that the ShinyHunters group is abusing in its hacking campaign targeting PeopleSoft customers. 

Oracle, which has not released a patch for the vulnerability at the time of writing, said in the advisory that the bug can be exploited over the internet without needing any authentication, such as a password. 

The tech giant recommended that customers who use PeopleSoft software apply its mitigations to prevent exploitation.

On Wednesday, a ShinyHunters member told TechCrunch that the gang compromised the companies by abusing an unpatched flaw in PeopleSoft servers. The bug is known as a zero-day because the company affected, in this case Oracle, had no time to fix it before it was discovered and exploited.

Mandiant confirmed that it has also notified more than “100 global organizations,” most of them in the United States, in an effort to restrict access to their potentially vulnerable systems. The cybersecurity group said that about two-thirds of these organizations are in higher education, which aligns with what ShinyHunters previously claimed.

“While several organizations successfully blocked the activity or remediated the vulnerabilities, others experienced compromise, resulting in stolen data being published on the ShinyHunters [Data Leak Website],” Mandiant wrote. 

See also  Nvidia's RTX Spark chip targets the Mac Studio, with Asus and MSI calling the first dibs

Oracle did not respond to TechCrunch’s request for comment. 

Contact Us

Do you have more information about this hacking campaign? Or other data breaches? We’d love to hear from you. From a non-work device and network, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.

The ShinyHunters member told TechCrunch this week that some of the hacked organizations are universities and colleges.

The hacker shared a message they said was sent to one of the victim schools, in which the hackers claimed to have stolen “hundreds of thousands of student records containing full name, home address, phone, email, date of birth, gender, ethnicity, enrollment status, GPA, major, and student ID across all campuses,” among other data. 

PeopleSoft, and its customers, are the latest victims in a long series of hacking campaigns where the ShinyHunters gang targeted organizations that all share the same vulnerable software. 

In the last year, the group targeted several companies that use Salesforce and Gainsight, as well as software provided by education giant Instructure, and among others. 

Once the hackers identify vulnerable software and companies that use it, they try to steal corporate or customer data and then threaten to release it unless the victims pay a ransom. 

Earlier this year, education tech company Instructure said it paid the hackers after they breached the company’s systems twice. As part of the hacking campaign, ShinyHunters defaced the login pages of several schools that use Instructure’s popular school information portal Canvas.

See also  Bank of England governor warns AI may need to be rationed because of energy limits

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.



Source link

abused breach bug companies hackers Oracle security warns
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

watchOS 27: Everything we know about the new features landing on your Apple Watch

June 11, 2026

Bluesky launches group chats, as company shifts focus to community features

June 11, 2026

Anthropic is spending $150M to embed 1,000 AI fellows inside nonprofits. No degree required.

June 11, 2026
Add A Comment

Leave A Reply Cancel Reply

Our Picks

watchOS 27: Everything we know about the new features landing on your Apple Watch

June 11, 2026

Bluesky launches group chats, as company shifts focus to community features

June 11, 2026

Anthropic is spending $150M to embed 1,000 AI fellows inside nonprofits. No degree required.

June 11, 2026

Ditch the Scam Anxiety and Lock Down Your Digital Life With Trend Micro

June 11, 2026
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Don't Miss
Uncategorized

watchOS 27: Everything we know about the new features landing on your Apple Watch

By June 11, 20260

At WWDC 2026, Apple announced watchOS 27, bringing Siri AI, a new Siri app, a…

Bluesky launches group chats, as company shifts focus to community features

June 11, 2026

Anthropic is spending $150M to embed 1,000 AI fellows inside nonprofits. No degree required.

June 11, 2026

Ditch the Scam Anxiety and Lock Down Your Digital Life With Trend Micro

June 11, 2026

Subscribe to Updates

Get the latest creative news from SmartMag about art & design.

About Us
About Us

Targeted Gaming delivers the best and most comprehensive video game and entertainment coverage, including news, reviews, trailers, walkthroughs, and guides for PS4, Xbox One, Nintendo Switch, PC, and More.

We're accepting new partnerships right now.

Latest Posts

watchOS 27: Everything we know about the new features landing on your Apple Watch

June 11, 2026

Bluesky launches group chats, as company shifts focus to community features

June 11, 2026

Anthropic is spending $150M to embed 1,000 AI fellows inside nonprofits. No degree required.

June 11, 2026
Sponsors

Type above and press Enter to search. Press Esc to cancel.