Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Oracle Responds to PeopleSoft Security Threat Amid Hacker Attacks

Oracle Responds to PeopleSoft Security Threat Amid Hacker Attacks

Posted on June 13, 2026 By CWS

Oracle has issued an urgent advisory on a newly discovered vulnerability in its PeopleSoft software, a widely used enterprise resource planning (ERP) suite. The flaw, identified as CVE-2026-35273, allows unauthorized attackers to execute remote code. This advisory follows reports of targeted attacks by the ShinyHunters hacker group, exploiting the vulnerability.

Details of the PeopleSoft Vulnerability

PeopleSoft is a comprehensive ERP solution that supports numerous business operations such as human resources, finance, and supply chain management. The critical vulnerability affects PeopleTools versions 8.61 and 8.62, potentially impacting users of PeopleSoft Enterprise Applications. Oracle has not yet provided a complete patch but has issued mitigation measures to address immediate risks.

Oracle has not confirmed whether the vulnerability has been actively exploited as a zero-day attack. However, they emphasized the importance of implementing the recommended mitigations to reduce the risk of exposure significantly.

Hacker Group Targeting PeopleSoft

The ShinyHunters hacker group has reportedly targeted over 300 PeopleSoft instances across more than 100 organizations. These cybercriminals are known for exploiting both old and zero-day vulnerabilities to access sensitive data, with the education sector being notably impacted. The University of Nottingham, among others, confirmed a major data breach, underscoring the threat’s seriousness.

ShinyHunters has a history of attacking widely-used enterprise software, previously targeting Salesforce customers in large-scale data theft operations. Security experts, including Mandiant CTO Charles Carmakal, have issued warnings about such zero-day exploitations.

Response and Recommendations

While Oracle’s advisory did not explicitly confirm in-the-wild exploitation, it is common for the company to withhold such details in public advisories. TrendAI researchers, credited with reporting the vulnerability, continue to investigate its exploitation extent. Dustin Childs, from TrendAI’s Zero Day Initiative, noted that while current exploitation is limited, ongoing investigations are crucial.

This development arrives shortly after CISA’s alert regarding another exploited Oracle WebLogic vulnerability. Organizations using PeopleSoft are urged to implement Oracle’s recommended mitigations promptly to protect against potential attacks.

Security experts and affected organizations are closely monitoring the situation, emphasizing the need for vigilance and rapid response strategies to safeguard enterprise systems against emerging cyber threats.

Security Week News Tags:cyber attack, Cybersecurity, data breach, enterprise security, ERP software, Oracle, PeopleSoft, remote code execution, ShinyHunters, zero-day vulnerability

Post navigation

Previous Post: INTERPOL Dismantles Sniper Dz Phishing Platform
Next Post: Arch Linux AUR Packages Hit by Massive Supply Chain Attack

Related Posts

Novee Emerges From Stealth With .5 Million in Funding Novee Emerges From Stealth With $51.5 Million in Funding Security Week News
US Cybersecurity Agency Flags Wi-Fi Range Extender Vulnerability Under Active Attack US Cybersecurity Agency Flags Wi-Fi Range Extender Vulnerability Under Active Attack Security Week News
AI Threats Loom: CISOs Urged to Strengthen Cybersecurity AI Threats Loom: CISOs Urged to Strengthen Cybersecurity Security Week News
North Korean Group Implicated in 0M Kelp DAO Crypto Theft North Korean Group Implicated in $290M Kelp DAO Crypto Theft Security Week News
175,000 Exposed Ollama Hosts Could Enable LLM Abuse 175,000 Exposed Ollama Hosts Could Enable LLM Abuse Security Week News
EU Cybersecurity Agency ENISA Launches European Vulnerability Database EU Cybersecurity Agency ENISA Launches European Vulnerability Database Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Bank of Baroda Confirms Email Security Breach
  • US, Australia Issue OT Isolation Guide for Infrastructure
  • Telegram Founder Pavel Durov Charged by Russia
  • Gitea Security Flaw Permits Remote Code Execution
  • OpenAI’s AI Models Breach Hugging Face Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Bank of Baroda Confirms Email Security Breach
  • US, Australia Issue OT Isolation Guide for Infrastructure
  • Telegram Founder Pavel Durov Charged by Russia
  • Gitea Security Flaw Permits Remote Code Execution
  • OpenAI’s AI Models Breach Hugging Face Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark