iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
CPKC sets second-quarter revenue record as operating income rises 10% Your Freight Funnel Is Leaking Margin: What Your Reports Won't Show Transponders Off: Saudi Crude Tankers for India Exit Red Sea 'Dark' to Avoid Houthi Blockade Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic, Deepening AI Rift For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis Chrome's AI-Driven Bug Hunt Spurs Twice-a-Week Security Patches, Google Reports Domestic Sugar Prices to Remain Firm in Short-Term, Says Triveni Engineering Saia’s Softer Q3 Margin Guidance Triggers 12% Share Drop Despite Record Q2 Results Buffalo meat and non-basmati rice lead 14% surge in India's Q1 agri exports Mahindra & Mahindra Records 34% Profit Jump Despite Commodity Cost Headwinds CPKC sets second-quarter revenue record as operating income rises 10% Your Freight Funnel Is Leaking Margin: What Your Reports Won't Show Transponders Off: Saudi Crude Tankers for India Exit Red Sea 'Dark' to Avoid Houthi Blockade Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic, Deepening AI Rift For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis Chrome's AI-Driven Bug Hunt Spurs Twice-a-Week Security Patches, Google Reports Domestic Sugar Prices to Remain Firm in Short-Term, Says Triveni Engineering Saia’s Softer Q3 Margin Guidance Triggers 12% Share Drop Despite Record Q2 Results Buffalo meat and non-basmati rice lead 14% surge in India's Q1 agri exports Mahindra & Mahindra Records 34% Profit Jump Despite Commodity Cost Headwinds
Home ›› Technology ›› Cybersecurity ›› Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations

Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations

Oracle has issued a security advisory for a critical remote code execution vulnerability (CVE-2026-35273, CVSS 9.8) in PeopleSoft versions 8.61 and 8.62. The extortion group ShinyHunters is exploiting it, claiming to have breached over 100 organizations and exfiltrated data from ~300 instances. Google's Mandiant reported zero-day exploitation between May 27 and June 9, 2026, and alerted over 100 potentially vulnerable entities.

iG
iGEN Editorial
June 15, 2026
Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations

Oracle has warned customers of a critical PeopleSoft vulnerability, tracked as CVE-2026-35273, being actively exploited by the ShinyHunters extortion group. The flaw, rated CVSS 9.8, allows remote code execution without authentication, posing a severe risk to enterprises relying on PeopleSoft for operations including supply chain and human resources management.

CVE-2026-35273: A Zero-Day Under Active Exploitation

According to Oracle's June 10, 2026 security advisory, the vulnerability is remotely exploitable without authentication and may result in remote code execution. Versions 8.61 and 8.62 of Oracle PeopleSoft are affected. Researchers from Google's Mandiant disclosed that they tracked exploitation of the flaw between May 27 and June 9, 2026, meaning it was used as a zero-day before Oracle released a patch.

ShinyHunters, a known extortion group, is reportedly behind the attacks. The group claims to have compromised more than 100 organizations and exfiltrated data from around 300 PeopleSoft instances. Victims have received ransom demands signed by ShinyHunters threatening to release stolen data unless payment is made. However, one researcher noted the possibility of "a group impersonating them," indicating the attackers may not have taken full credit yet.

Google Mandiant Alerts Over 100 Organizations

Google's Mandiant informed over 100 global organizations whose IP addresses correlated with potentially vulnerable endpoints. Of these, 68% were higher education institutions, and the majority of victims were based in the United States. Mandiant urged organizations to check logs for suspicious access between late May and early June and to apply Oracle's security update regardless of whether an attack has been detected.

PeopleSoft Version Status Recommended Action
8.61 Affected Apply patch immediately
8.62 Affected Apply patch immediately

Immediate Actions for Oracle PeopleSoft Users

Oracle is urging users to take "immediate action" to apply the security patch. The advisory emphasizes the critical nature of CVE-2026-35273, which carries a CVSS score of 9.8 out of 10. Organizations that have not yet patched should prioritize this update, especially those in sectors like higher education, public sector, and business services.

Mandiant also recommends reviewing access logs for any unauthorized activity from late May 2026 onward. Given the zero-day nature of the exploit, even organizations not yet contacted by Mandiant should assume potential exposure and act swiftly.

Implications for International Trade Operations

While the primary victims reported are academic institutions, enterprises using PeopleSoft for trade-related functions — such as customs compliance, freight management, and supplier portals — are equally at risk. A successful exploit could lead to data exfiltration of sensitive commercial information, including shipping manifests, contract terms, and partner databases. Ransom demands could disrupt operations if payment is withheld or data is leaked.

For international trade executives, this attack highlights the need to verify that enterprise resource planning (ERP) systems are patched and monitored. The vulnerability's remote, unauthenticated nature means that any exposed PeopleSoft instance could be targeted, regardless of geographic location. Companies should coordinate with their IT security teams to confirm patch status and review Mandiant's threat intelligence.

What to Watch

The authenticity of ShinyHunters' involvement remains under investigation, but the exploitation window (May 27–June 9) predates Oracle's patch. Organizations should monitor Mandiant's updates and Oracle's advisory for further intelligence. The next key milestone will be evidence of whether data from trade-related entities has been publicly leaked.


Sources: TechRadar – Main Feed

Keep Reading

Recommended Stories

Google Urges Immediate Chrome Update to Fix Zero-Day Flaw Technology

Google Urges Immediate Chrome Update to Fix Zero-Day Flaw

Google has released a patch for a high-severity zero-day vulnerability in Chrome, identified as CVE-2026-11645. The flaw allows remote code execution and is actively exploited. Users should update Chrome immediately to version 149.0.7827.103 or later.

June 9, 2026
Linux Kernel Vulnerability: A Single Character Threat Technology

Linux Kernel Vulnerability: A Single Character Threat

A logic inversion bug in the Linux kernel, identified as CVE-2026-23111, allows privilege escalation, affecting major distributions like Debian, Ubuntu, and RHEL. The vulnerability highlights challenges in managing AI-driven bug reports.

June 9, 2026
Hidden Car Alarm Device in Millions of US Vehicles Is a Hacking Risk – Patch Now Technology

Hidden Car Alarm Device in Millions of US Vehicles Is a Hacking Risk – Patch Now

UC San Diego researchers discovered a severe Bluetooth vulnerability in the KARR Security System aftermarket car alarm, installed by dealers in over 2 million vehicles across the US. The flaw allows attackers to unlock, track, or disable ignition from Bluetooth range. Acrisure Protection Group has released a firmware patch; owners must manually update via the KARR app.

July 21, 2026
AI Found a Root Bug in Linux That Everyone Missed for 15 Years Technology

AI Found a Root Bug in Linux That Everyone Missed for 15 Years

A Linux kernel use-after-free vulnerability, GhostLock (CVE-2026-43499), went undetected for 15 years until Nebula Security's AI bug-hunting tool VEGA found it. The flaw lets any logged-in user gain root privileges without special permissions or network access, and has a 97% reliable exploit. Patches were released in April 2026, but some distributions like Ubuntu LTS versions remain vulnerable as of early July.

July 11, 2026