news.mlab.sh
Back to the feed
vulnerability

Oracle mitigates PeopleSoft zero-day exploited in data theft attacks

Critical
Summary

A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools has been exploited by the ShinyHunters ransomware gang to steal data from numerous organizations. Oracle has released mitigations, but the ongoing exploitation highlights the risk posed by unpatched systems and the group's sophisticated attack techniques. This incident underscores the importance of proactive vulnerability management and continuous monitoring.

The vulnerability, affecting PeopleSoft PeopleTools versions 8.61 and 8.62, allows for unauthenticated remote code execution. This was actively exploited by the ShinyHunters group, who targeted approximately 300 instances across over 100 organizations, allegedly stealing data and leaving ransom notes. The group is known for targeting cloud SaaS instances, CRMs, and enterprise platforms, utilizing a ‘gadget chain’ of old and zero-day flaws to gain access. Cybersecurity researcher ‘Michael R’ identified several IP addresses associated with the attacks, further illustrating the breadth of the compromise. The incident highlights the potential damage caused by exploiting unpatched software and the evolving tactics of sophisticated threat actors.

Read the full article at BleepingComputer