ShinyHunters breached 100+ companies through an unpatched Oracle PeopleSoft zero-day


TL;DR

ShinyHunters exploited an unpatched Oracle PeopleSoft zero-day (CVE-2026-35273, CVSS 9.8) to breach 100+ organisations. Two-thirds are universities. No patch yet.

Oracle warned customers on Thursday of a critical vulnerability in its PeopleSoft software that hackers have already exploited to breach more than 100 organisations. The flaw, CVE-2026-35273, carries a CVSS score of 9.8 and can be exploited over the internet without any authentication. Oracle has not released a patch.

The advisory came a day after the cybercrime group ShinyHunters claimed responsibility for the mass-hacking campaign. Google’s Mandiant confirmed that the bug Oracle disclosed is the same one ShinyHunters is exploiting. Mandiant said it notified more than 100 global organisations, most of them in the United States.

About two-thirds of the victims are universities and colleges. A ShinyHunters member told TechCrunch the group stole “hundreds of thousands of student records containing full name, home address, phone, email, date of birth, gender, ethnicity, enrollment status, GPA, major, and student ID.” The University of Nottingham was named among the breached institutions.

The 💜 of EU tech

The latest rumblings from the EU tech scene, a story from our wise ol’ founder Boris, and some questionable AI art. It’s free, every week, in your inbox. Sign up now!

While several organizations successfully blocked the activity or remediated the vulnerabilities, others experienced compromise, resulting in stolen data being published on the ShinyHunters Data Leak Website,” Mandiant wrote. Oracle did not respond to TechCrunch’s request for comment.

PeopleSoft is used by large companies and universities to manage payroll, human resources, and student records. The vulnerability affects PeopleTools versions 8.61 and 8.62. ShinyHunters exploited a chain of old and zero-day vulnerabilities to target both cloud and on-premises instances, compromising approximately 300 servers across the 100+ organisations.

The attack follows a pattern. ShinyHunters has spent the past year targeting organisations that share the same vulnerable enterprise software. Previous campaigns hit companies using Salesforce, Gainsight, and education platform Instructure. The group identifies the flaw, finds every company running the software, steals data, and demands a ransom.

Instructure paid the hackers earlier this year after being breached twice. ShinyHunters also defaced the login pages of schools using Instructure’s Canvas portal. The PeopleSoft campaign is the largest yet, and it is ongoing. Oracle recommended mitigations but has not said when a patch will be available.

For any organisation running PeopleSoft, the immediate action is to apply Oracle’s mitigations and restrict internet-facing access to PeopleSoft servers. The broader lesson is one the enterprise software industry keeps relearning: when a critical zero-day hits software used by hundreds of large organisations, the attacker only needs to find it once. AI is making vulnerability discovery cheaper. The defenders patching those flaws are not getting faster. And groups like ShinyHunters are industrialising the exploitation of every window between disclosure and fix.



Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Reaching people who have been let down so many times they’ve stopped expecting anything different takes time, consistency, and trust. The Winter Surge project does all these things and more.

Running every November to March for the past four years, the Winter Surge project – part of our Higher Needs Floating Support service – provides high support temporary accommodation for 17 beds, daily welfare checks, and intensive, trauma-informed care for Bristol’s most entrenched rough sleepers.

Commissioned by Bristol City Council as part of its cold weather provision, it brings together a powerful network of partners including St Mungo’s Outreach, Social Care, Homeless Health, drug and alcohol services and housing providers.

Team Manager Sam Scott has been involved in shaping the project from the start – from planning how it works and selecting temporary accommodation providers, to troubleshooting, managing risk, and feeding back learning to improve the service year-on-year. She says it has been a privilege:

Bristol City Council gave me the opportunity to run Winter Surge and the autonomy to shape it into what it’s become. From the planning stages right through to being on the ground – it’s an extraordinary project to be part of.”

A landmark year

This winter, 42 people came into the service and not one of them went back to the streets. This is the result of a small, skilled team of support workers focused on stabilisation, move-on planning, and wrap-around support covering mental health, safeguarding, benefits, addiction, and wellbeing. After the project ended on 31 March, the wider team makes sure clients move on from the service smoothly with no gap in care.

There are some truly amazing personal stories hidden behind the headline numbers. Four clients who had resisted support for years agreed to come in and stayed for the full duration. One man, who had been living with undiagnosed cancer for over three years, was supported by the team to access hospital treatment. He has now had two major operations and is receiving ongoing care. Sam said:

It’s our patient, trauma-informed relationship building that makes all the difference. I’m so proud of the team and the work we’ve done, particularly this year when not one person went back onto the streets.”

Building trust where it’s been broken

At the heart of the Winter Surge is a commitment to breaking the cycle that sees the most vulnerable people going through many services and feeling constantly let down. The project successfully reduced evictions, improved access to housing, rebuilt confidence in receiving support, and promoted a My Team Around Me approach, ensuring every agency took genuine ownership of their role in a client’s journey.

This is what person-centred, trauma-informed care looks like in practice, and this year it worked for every single person who walked through the door.

Image L-R: Amy O’Loughlin, Sam Scott, Emma Ireland



Source link