Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert
ID: 302c1e15-3fa0-5f55-b69d-5344ada93d42
STIX ID: report--302c1e15-3fa0-5f55-b69d-5344ada93d42
Feed Name: Help Net Security
A zero-day RCE vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools is being exploited in the wild, and Oracle has published an out-of-band alert; security firms report active exploitation and limited patch visibility. Concurrently, the ShinyHunters extortion group claims to have breached over 100 organizations via PeopleSoft, leaking tens of gigabytes of personal and academic data (affecting up to ~500k people), while researchers published related IPs, domains, and tooling used in the intrusions to help defenders detect compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
