viernes, 12 de junio de 2026

ShinyHunters Exploits Oracle Zero-Day Breaching 100 Organisations

A critical security vulnerability in Oracle's PeopleSoft software has been exploited by the notorious cybercrime group ShinyHunters to breach over 100 organisations worldwide, with no patch currently available. The flaw, designated CVE-2026-35273, carries an alarming CVSS severity score of 9.8 out of 10, making it one of the most critical vulnerabilities disclosed this year. What makes this particularly dangerous is that attackers can exploit it remotely over the internet without requiring any authentication credentials whatsoever.

ShinyHunters Exploits Oracle Zero-Day Breaching 100+ Organisations

Oracle issued an urgent warning to customers on Thursday, acknowledging the vulnerability just one day after ShinyHunters publicly claimed responsibility for the mass-hacking campaign. Google's cybersecurity division, Mandiant, confirmed that the vulnerability Oracle disclosed is indeed the same zero-day exploit being weaponised by the criminal group. Mandiant has already notified more than 100 affected organisations globally, with the majority located in the United States.

The victims are predominantly educational institutions, with approximately two-thirds being universities and colleges. A ShinyHunters member revealed to TechCrunch that the group successfully stole hundreds of thousands of student records containing highly sensitive personal information, including full names, home addresses, phone numbers, email addresses, dates of birth, gender, ethnicity, enrolment status, grade point averages, academic majors, and student identification numbers. The University of Nottingham has been publicly identified amongst the compromised institutions.

PeopleSoft is enterprise software widely deployed by large corporations and universities to manage critical functions such as payroll processing, human resources, and student records management. The vulnerability specifically affects PeopleTools versions 8.61 and 8.62. ShinyHunters demonstrated sophisticated technical capabilities by chaining together both previously known vulnerabilities and new zero-day exploits to compromise approximately 300 servers across both cloud-based and on-premises installations.

This attack represents the latest in a concerning pattern of behaviour from ShinyHunters, who have spent the past year systematically targeting organisations using the same vulnerable enterprise software platforms. Previous campaigns successfully breached companies using Salesforce, Gainsight, and the education platform Instructure. Their methodology is devastatingly effective: identify a vulnerability, locate every organisation running the affected software, steal valuable data, and demand ransom payments. Instructure notably paid the hackers earlier this year after suffering two separate breaches, and ShinyHunters also defaced login pages of educational institutions using Instructure's Canvas portal. The PeopleSoft campaign is their largest operation to date and remains actively ongoing. Whilst Oracle has recommended temporary mitigations, the company has not provided any timeline for when a permanent security patch will be released.

Fuente Original: https://thenextweb.com/news/oracle-peoplesoft-shinyhunters-zero-day-100-companies

Artículos relacionados de LaRebelión:

Artículo generado mediante LaRebelionBOT

No hay comentarios:

Publicar un comentario