Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Nissan Data Breach Linked to Oracle PeopleSoft Exploit

Nissan Data Breach Linked to Oracle PeopleSoft Exploit

Posted on June 30, 2026 By CWS

Nissan Americas has revealed that a data breach has affected both current and past employees across four nations. This breach resulted from the exploitation of a critical vulnerability within Oracle PeopleSoft software, attributed to the cybercriminal group known as ShinyHunters.

Details of the Oracle PeopleSoft Vulnerability

The attack exploited CVE-2026-35273, a severe vulnerability with a CVSS score of 9.8, identified in the Updates Environment Management (PSEMHUB) component of Oracle PeopleSoft PeopleTools versions 8.61 and 8.62. This flaw allows remote code execution without the need for authentication or user interaction, making it highly dangerous. Oracle responded with an emergency security patch on June 10, 2026, and CISA promptly included the vulnerability in its Known Exploited Vulnerabilities catalog.

Impact on Nissan and Employee Data

According to notifications submitted to the California Attorney General’s Office, Nissan Americas was specifically targeted in this attack. The breach, occurring between May 27 and June 9, 2026, potentially exposed sensitive employee data such as contact information, banking details, Social Security and Insurance Numbers, and financial and tax information. The breach affects employees in the United States, Canada, Mexico, and Brazil.

Nissan has activated its incident response protocols, including engaging cybersecurity experts and law enforcement. To contain the breach, access to payroll systems has been restricted, requiring secure VPN connections and additional authentication measures. Affected individuals are being offered free credit and dark web monitoring services.

Technical Analysis and Indicators of Compromise

Mandiant’s analysis indicates that ShinyHunters deployed remote management agents disguised as legitimate services, facilitating data exfiltration and internal reconnaissance. Compromised servers were marked with a ransom note file. Key indicators of compromise include specific IP addresses and domains used for command and control operations.

Organizations using PeopleTools 8.61 or 8.62 are urged to prioritize patching. Additional recommendations include disabling the PSEMHUB service, monitoring outbound traffic for suspicious activities, and rotating credentials from potentially compromised systems.

This breach underscores the evolving threat landscape for ERP systems, following similar exploits in recent months. Strengthening security operations and accelerating threat detection remain critical for organizations to protect against such sophisticated attacks.

Cyber Security News Tags:CVE-2026-35273, Cybercrime, Cybersecurity, data breach, Google Threat Intelligence, Mandiant, Nissan, Oracle PeopleSoft, ShinyHunters, Vulnerability

Post navigation

Previous Post: Gemini CLI Flaw Allows Arbitrary Code Execution in CI/CD
Next Post: Vulnerabilities in Daktronics Controllers Pose Hacking Risks

Related Posts

Windows 11 24H2/25H2 Update Causes Task Manager to be Active After Closure Windows 11 24H2/25H2 Update Causes Task Manager to be Active After Closure Cyber Security News
SideWinder Hacking Group Uses ClickOnce-Based Infection Chain to Deploy StealerBot Malware SideWinder Hacking Group Uses ClickOnce-Based Infection Chain to Deploy StealerBot Malware Cyber Security News
A Buyer’s Guide for CISOs A Buyer’s Guide for CISOs Cyber Security News
Hackers Actively Exploiting Cisco and Citrix 0-Days in the Wild to Deploy Webshell Hackers Actively Exploiting Cisco and Citrix 0-Days in the Wild to Deploy Webshell Cyber Security News
Cisco Acquires Astrix to Bolster AI Identity Security Cisco Acquires Astrix to Bolster AI Identity Security Cyber Security News
Microsoft’s KB5121767 Update Resolves Dell USB-C Issues Microsoft’s KB5121767 Update Resolves Dell USB-C Issues Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • RingCentral Data Breach Exposes 1.6 Million Records
  • Hackers Exploit AI Token Jacking for Major API Key Theft
  • Data Breach Hits Over 1,000 Charities Using Beacon CRM
  • New RAM Exploit Bypasses Windows Security Barriers
  • Trezor Customer Data Exposed in ShipMonk Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • RingCentral Data Breach Exposes 1.6 Million Records
  • Hackers Exploit AI Token Jacking for Major API Key Theft
  • Data Breach Hits Over 1,000 Charities Using Beacon CRM
  • New RAM Exploit Bypasses Windows Security Barriers
  • Trezor Customer Data Exposed in ShipMonk Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark