
Oracle has raised an alarm among its enterprise clients regarding a serious vulnerability within its PeopleSoft software, which is widely used for payroll and human resources management. This warning comes shortly after the cybercriminal group ShinyHunters claimed responsibility for breaches affecting more than 100 organizations utilizing PeopleSoft servers. The tech giant issued a security advisory on Thursday, highlighting that the flaw can be exploited remotely without the need for authentication, such as passwords. Mandiant, a security firm owned by Google that specializes in investigating cyberattacks, confirmed that the vulnerability being exploited by ShinyHunters is indeed the same one identified in Oracle's advisory. As of now, Oracle has not provided a patch for this vulnerability, prompting the company to recommend that its PeopleSoft users implement specific mitigations to safeguard their systems. A representative from ShinyHunters disclosed to TechCrunch that the group successfully compromised these organizations by taking advantage of the unpatched flaw. This vulnerability is classified as a zero-day, meaning that Oracle had not yet addressed it before it was discovered and exploited by hackers. Mandiant reported that it has proactively informed over 100 global entities, predominantly in the United States, about the potential risks to their systems, particularly noting that around two-thirds of these organizations are affiliated with higher education. While some institutions were able to thwart the hacking attempts or remediate the vulnerabilities, others faced data breaches that resulted in sensitive information being leaked on the ShinyHunters data leak website. The group revealed that among the compromised organizations are universities and colleges, claiming to have accessed extensive student records containing personal details such as names, addresses, and academic information. This incident marks another chapter in a series of hacking campaigns orchestrated by the ShinyHunters gang, which has previously targeted various companies utilizing popular software, including Salesforce and Gainsight. Their method typically involves identifying vulnerable systems, stealing data, and threatening to publish it unless a ransom is paid. Earlier this year, Instructure, an education technology company, admitted to paying a ransom after being breached twice. As the situation unfolds, Oracle has yet to respond to inquiries from TechCrunch regarding the incident.
The realm of scientific research is undergoing a profound transformation, fueled by the rapid advancements in artificial...
Business Today | Jul 25, 2026, 24:30
In recent discussions, a once-obscure topic in artificial intelligence has surged to the forefront of debates among tech...
CNBC | Jul 25, 2026, 12:15
On Friday evening, SpaceX executed a significant milestone by launching its colossal Starship rocket from its facility i...
CNBC | Jul 25, 2026, 24:10
On Friday, SpaceX marked a significant achievement by successfully launching its first batch of third-generation Starlin...
TechCrunch | Jul 24, 2026, 23:40
Kalshi, the prediction market platform, has taken significant legal steps against Netflix, sending a cease-and-desist le...
TechCrunch | Jul 25, 2026, 17:10