Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Oracle Responds to PeopleSoft Security Threat Amid Hacker Attacks

Oracle Responds to PeopleSoft Security Threat Amid Hacker Attacks

Posted on June 13, 2026 By CWS

Oracle has issued an urgent advisory on a newly discovered vulnerability in its PeopleSoft software, a widely used enterprise resource planning (ERP) suite. The flaw, identified as CVE-2026-35273, allows unauthorized attackers to execute remote code. This advisory follows reports of targeted attacks by the ShinyHunters hacker group, exploiting the vulnerability.

Details of the PeopleSoft Vulnerability

PeopleSoft is a comprehensive ERP solution that supports numerous business operations such as human resources, finance, and supply chain management. The critical vulnerability affects PeopleTools versions 8.61 and 8.62, potentially impacting users of PeopleSoft Enterprise Applications. Oracle has not yet provided a complete patch but has issued mitigation measures to address immediate risks.

Oracle has not confirmed whether the vulnerability has been actively exploited as a zero-day attack. However, they emphasized the importance of implementing the recommended mitigations to reduce the risk of exposure significantly.

Hacker Group Targeting PeopleSoft

The ShinyHunters hacker group has reportedly targeted over 300 PeopleSoft instances across more than 100 organizations. These cybercriminals are known for exploiting both old and zero-day vulnerabilities to access sensitive data, with the education sector being notably impacted. The University of Nottingham, among others, confirmed a major data breach, underscoring the threat’s seriousness.

ShinyHunters has a history of attacking widely-used enterprise software, previously targeting Salesforce customers in large-scale data theft operations. Security experts, including Mandiant CTO Charles Carmakal, have issued warnings about such zero-day exploitations.

Response and Recommendations

While Oracle’s advisory did not explicitly confirm in-the-wild exploitation, it is common for the company to withhold such details in public advisories. TrendAI researchers, credited with reporting the vulnerability, continue to investigate its exploitation extent. Dustin Childs, from TrendAI’s Zero Day Initiative, noted that while current exploitation is limited, ongoing investigations are crucial.

This development arrives shortly after CISA’s alert regarding another exploited Oracle WebLogic vulnerability. Organizations using PeopleSoft are urged to implement Oracle’s recommended mitigations promptly to protect against potential attacks.

Security experts and affected organizations are closely monitoring the situation, emphasizing the need for vigilance and rapid response strategies to safeguard enterprise systems against emerging cyber threats.

Security Week News Tags:cyber attack, Cybersecurity, data breach, enterprise security, ERP software, Oracle, PeopleSoft, remote code execution, ShinyHunters, zero-day vulnerability

Post navigation

Previous Post: INTERPOL Dismantles Sniper Dz Phishing Platform
Next Post: Arch Linux AUR Packages Hit by Massive Supply Chain Attack

Related Posts

Latvian Hacker Jailed for Karakurt Ransomware Crimes Latvian Hacker Jailed for Karakurt Ransomware Crimes Security Week News
GlassWorm Malware Tied to Over 70 Open VSX Clones GlassWorm Malware Tied to Over 70 Open VSX Clones Security Week News
Hackers Stole 300,000 Crash Reports From Texas Department of Transportation Hackers Stole 300,000 Crash Reports From Texas Department of Transportation Security Week News
Lenovo Firmware Vulnerabilities Allow Persistent Implant Deployment Lenovo Firmware Vulnerabilities Allow Persistent Implant Deployment Security Week News
GlassWorm Malware Tied to Over 70 Open VSX Clones VS Code Flaws in GitHub Codespaces Risk Supply Chain Attacks Security Week News
Flaw Allowing Website Takeover Found in WordPress Plugin With 400k Installations Flaw Allowing Website Takeover Found in WordPress Plugin With 400k Installations Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Anthropic Pauses AI Models Amid U.S. Export Controls
  • U.S. Halts Foreign Access to Anthropic’s AI Models
  • SHEETCREEP RAT Exploits Google Sheets for Covert Ops
  • CISA Urges Agencies to Address High-Risk Security Flaws
  • Security Flaws in OpenClaw AI: New Research Reveals Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Anthropic Pauses AI Models Amid U.S. Export Controls
  • U.S. Halts Foreign Access to Anthropic’s AI Models
  • SHEETCREEP RAT Exploits Google Sheets for Covert Ops
  • CISA Urges Agencies to Address High-Risk Security Flaws
  • Security Flaws in OpenClaw AI: New Research Reveals Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark