A critical security vulnerability in Oracle's PeopleSoft software has been exploited by the notorious cybercrime group ShinyHunters to breach over 100 organisations worldwide, with no patch currently available. The flaw, designated CVE-2026-35273, carries an alarming CVSS severity score of 9.8 out of 10, making it one of the most critical vulnerabilities disclosed this year. What makes this particularly dangerous is that attackers can exploit it remotely over the internet without requiring any authentication credentials whatsoever.

Oracle issued an urgent warning to customers on Thursday, acknowledging the vulnerability just one day after ShinyHunters publicly claimed responsibility for the mass-hacking campaign. Google's cybersecurity division, Mandiant, confirmed that the vulnerability Oracle disclosed is indeed the same zero-day exploit being weaponised by the criminal group. Mandiant has already notified more than 100 affected organisations globally, with the majority located in the United States.
The victims are predominantly educational institutions, with approximately two-thirds being universities and colleges. A ShinyHunters member revealed to TechCrunch that the group successfully stole hundreds of thousands of student records containing highly sensitive personal information, including full names, home addresses, phone numbers, email addresses, dates of birth, gender, ethnicity, enrolment status, grade point averages, academic majors, and student identification numbers. The University of Nottingham has been publicly identified amongst the compromised institutions.
PeopleSoft is enterprise software widely deployed by large corporations and universities to manage critical functions such as payroll processing, human resources, and student records management. The vulnerability specifically affects PeopleTools versions 8.61 and 8.62. ShinyHunters demonstrated sophisticated technical capabilities by chaining together both previously known vulnerabilities and new zero-day exploits to compromise approximately 300 servers across both cloud-based and on-premises installations.
This attack represents the latest in a concerning pattern of behaviour from ShinyHunters, who have spent the past year systematically targeting organisations using the same vulnerable enterprise software platforms. Previous campaigns successfully breached companies using Salesforce, Gainsight, and the education platform Instructure. Their methodology is devastatingly effective: identify a vulnerability, locate every organisation running the affected software, steal valuable data, and demand ransom payments. Instructure notably paid the hackers earlier this year after suffering two separate breaches, and ShinyHunters also defaced login pages of educational institutions using Instructure's Canvas portal. The PeopleSoft campaign is their largest operation to date and remains actively ongoing. Whilst Oracle has recommended temporary mitigations, the company has not provided any timeline for when a permanent security patch will be released.
Fuente Original: https://thenextweb.com/news/oracle-peoplesoft-shinyhunters-zero-day-100-companies
Artículos relacionados de LaRebelión:
- Microsoft Defender Zero-Day Vulnerability Exposes Windows Systems
- IA Descubre 21 Vulnerabilidades Zero-Day en FFmpeg
- IA en Ciberataques Agentes LLM Tras Exploits
- Exploit Zero-Day Derrota Proteccion BitLocker Windows 11
- Anthropics AI Discovers Thousands of Zero-Day Vulnerabilities
Artículo generado mediante LaRebelionBOT
No hay comentarios:
Publicar un comentario