PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data

PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data

A significant vulnerability in Oracle's PeopleSoft software has been actively exploited by one of the world's most notorious ransomware groups, known as ShinyHunters. This group has reportedly targeted around 100 organizations, successfully extorting at least one victim by threatening to release stolen data. The vulnerability, identified as CVE-2026-35273, has a critical severity rating of 9.8 out of 10, marking it as one of the most severe zero-day vulnerabilities detected this year. According to researchers from Google’s Mandiant security team, the flaw is classified as a server-side request forgery (SSRF), which allows attackers to send requests from a vulnerable server to other systems within the targeted organization. Oracle has acknowledged the issue, stating that the SSRF vulnerability is remotely exploitable and has issued a temporary mitigation solution. However, a complete patch for the flaw has not yet been rolled out. Meanwhile, Mandiant has confirmed that victims of the attacks are facing extortion demands from the group. Among the affected entities, the University of Nottingham recently confirmed that it had fallen victim to the breach, resulting in a “significant” amount of student data being compromised. This announcement followed ShinyHunters' claim that the university was among its latest targets, as they released gigabytes of data purportedly obtained from the hack. Since May 27, ShinyHunters has been exploiting this vulnerability, and as of mid-week, they had targeted approximately 300 endpoints across 100 organizations, with around 68% of these belonging to the higher education sector. Researchers have noted that the group has exposed several directories that indicate ongoing attacks on PeopleSoft, and they have even left a staging server accessible, containing tools used during the attack.

Sources : Ars Technica

Published On : Jun 12, 2026, 19:30

Science
Could Early Detection Have Mitigated Ozone Layer Damage?

The global ban on substances that deplete the ozone layer is widely viewed as a successful environmental initiative that...

Ars Technica | Jun 29, 2026, 19:05
Could Early Detection Have Mitigated Ozone Layer Damage?
Cybersecurity
Supreme Court Limits Government Access to Personal Location Data

In a significant ruling on Monday, the Supreme Court affirmed that the Fourth Amendment guards an individual's "location...

Ars Technica | Jun 29, 2026, 20:05
Supreme Court Limits Government Access to Personal Location Data
Science
Solar Energy Surpasses Coal for the First Time, Yet Challenges Remain

In a remarkable shift within the U.S. energy landscape, preliminary reports reveal that solar power has officially eclip...

Ars Technica | Jun 29, 2026, 20:15
Solar Energy Surpasses Coal for the First Time, Yet Challenges Remain
Cybersecurity
FBI Offers $10 Million Reward for Leads on Russian Hackers Targeting Signal and WhatsApp

In a significant move to combat cyber threats, federal authorities have announced a reward of up to $10 million for info...

Ars Technica | Jun 29, 2026, 22:10
FBI Offers $10 Million Reward for Leads on Russian Hackers Targeting Signal and WhatsApp
Startups
Base44 Unveils Proprietary AI Model to Enhance App Development Efficiency

Base44, the innovative vibe coding platform snapped up by Wix for $80 million just a year ago, is making headlines with ...

TechCrunch | Jun 30, 2026, 02:45
Base44 Unveils Proprietary AI Model to Enhance App Development Efficiency
View All News