• Homepage
  • News
  • eSports
  • PC
  • Playstation
  • Xbox
  • Nintendo
  • Reviews
  • Cosplay
What's Hot

What makes a laptop good for both work and entertainment?

June 11, 2026

Coinbase’s new tool can help agents trade and pay for premium research

June 11, 2026

How companies train millions of workers when their products never stop shipping

June 11, 2026
Facebook Twitter Instagram
  • Contact
  • Terms & Conditions
  • Privacy Policy
Facebook Twitter Instagram
Gaming MasterGaming Master
Subscribe
  • Homepage
  • News
  • eSports
  • PC
  • Playstation
  • Xbox
  • Nintendo
  • Reviews
  • Cosplay
Gaming MasterGaming Master
Home»Uncategorized»ShinyHunters breached 100+ companies through an unpatched Oracle PeopleSoft zero-day
Uncategorized

ShinyHunters breached 100+ companies through an unpatched Oracle PeopleSoft zero-day

By June 11, 2026No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


TL;DR

ShinyHunters exploited an unpatched Oracle PeopleSoft zero-day (CVE-2026-35273, CVSS 9.8) to breach 100+ organisations. Two-thirds are universities. No patch yet.

Oracle warned customers on Thursday of a critical vulnerability in its PeopleSoft software that hackers have already exploited to breach more than 100 organisations. The flaw, CVE-2026-35273, carries a CVSS score of 9.8 and can be exploited over the internet without any authentication. Oracle has not released a patch.

The advisory came a day after the cybercrime group ShinyHunters claimed responsibility for the mass-hacking campaign. Google’s Mandiant confirmed that the bug Oracle disclosed is the same one ShinyHunters is exploiting. Mandiant said it notified more than 100 global organisations, most of them in the United States.

About two-thirds of the victims are universities and colleges. A ShinyHunters member told TechCrunch the group stole “hundreds of thousands of student records containing full name, home address, phone, email, date of birth, gender, ethnicity, enrollment status, GPA, major, and student ID.” The University of Nottingham was named among the breached institutions.

The 💜 of EU tech

The latest rumblings from the EU tech scene, a story from our wise ol’ founder Boris, and some questionable AI art. It’s free, every week, in your inbox. Sign up now!

“While several organizations successfully blocked the activity or remediated the vulnerabilities, others experienced compromise, resulting in stolen data being published on the ShinyHunters Data Leak Website,” Mandiant wrote. Oracle did not respond to TechCrunch’s request for comment.

PeopleSoft is used by large companies and universities to manage payroll, human resources, and student records. The vulnerability affects PeopleTools versions 8.61 and 8.62. ShinyHunters exploited a chain of old and zero-day vulnerabilities to target both cloud and on-premises instances, compromising approximately 300 servers across the 100+ organisations.

See also  Lexus halts plans of an electric car based on the stunning LF-ZC concept and it's such a bummer

The attack follows a pattern. ShinyHunters has spent the past year targeting organisations that share the same vulnerable enterprise software. Previous campaigns hit companies using Salesforce, Gainsight, and education platform Instructure. The group identifies the flaw, finds every company running the software, steals data, and demands a ransom.

Instructure paid the hackers earlier this year after being breached twice. ShinyHunters also defaced the login pages of schools using Instructure’s Canvas portal. The PeopleSoft campaign is the largest yet, and it is ongoing. Oracle recommended mitigations but has not said when a patch will be available.

For any organisation running PeopleSoft, the immediate action is to apply Oracle’s mitigations and restrict internet-facing access to PeopleSoft servers. The broader lesson is one the enterprise software industry keeps relearning: when a critical zero-day hits software used by hundreds of large organisations, the attacker only needs to find it once. AI is making vulnerability discovery cheaper. The defenders patching those flaws are not getting faster. And groups like ShinyHunters are industrialising the exploitation of every window between disclosure and fix.



Source link

breached companies Oracle PeopleSoft ShinyHunters unpatched zeroday
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

What makes a laptop good for both work and entertainment?

June 11, 2026

Coinbase’s new tool can help agents trade and pay for premium research

June 11, 2026

How companies train millions of workers when their products never stop shipping

June 11, 2026
Add A Comment

Leave A Reply Cancel Reply

Our Picks

What makes a laptop good for both work and entertainment?

June 11, 2026

Coinbase’s new tool can help agents trade and pay for premium research

June 11, 2026

How companies train millions of workers when their products never stop shipping

June 11, 2026

Pixar just dropped the Gatto movie trailer and it has everything a cat lover could want

June 11, 2026
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Don't Miss
Uncategorized

What makes a laptop good for both work and entertainment?

By June 11, 20260

This post is brought to you in paid partnership with HP. The HP OmniBook X Flip…

Coinbase’s new tool can help agents trade and pay for premium research

June 11, 2026

How companies train millions of workers when their products never stop shipping

June 11, 2026

Pixar just dropped the Gatto movie trailer and it has everything a cat lover could want

June 11, 2026

Subscribe to Updates

Get the latest creative news from SmartMag about art & design.

About Us
About Us

Targeted Gaming delivers the best and most comprehensive video game and entertainment coverage, including news, reviews, trailers, walkthroughs, and guides for PS4, Xbox One, Nintendo Switch, PC, and More.

We're accepting new partnerships right now.

Latest Posts

What makes a laptop good for both work and entertainment?

June 11, 2026

Coinbase’s new tool can help agents trade and pay for premium research

June 11, 2026

How companies train millions of workers when their products never stop shipping

June 11, 2026
Sponsors

Type above and press Enter to search. Press Esc to cancel.