Oracle warns customers of a critical PeopleSoft flaw after ShinyHunters claimed it breached 100+ organizations that use PeopleSoft; Oracle hasn't issued a patch
TechCrunchLorenzo Franceschi-Bicchierai
Context & Ripple Effects
This follows a recent Oracle advisory on an exploited E-Business Suite vulnerability and reports that Oracle had disclosed stolen legacy credentials to some clients. Together, the coverage puts PeopleSoft in a broader pattern of security pressure around Oracle’s enterprise-software estate.
The claimed scale of ShinyHunters’ activity raises the stakes because the affected software sits with many organizations, while Oracle has not yet provided a patch.
First-order effects
PeopleSoft customers must assess exposure and apply available mitigations or monitoring without waiting for a vendor fix; organizations named or potentially affected by the claimed intrusions also face immediate incident-response work.
Oracle must communicate compensating controls and customer guidance under heightened scrutiny, despite the breach claims not being independently established in the supplied coverage.
Second-order effects
Security teams may prioritize reviews of connected identity systems, credentials, and externally reachable enterprise applications, especially after the separate reports involving Oracle customer credentials and E-Business Suite exploitation.
Other vendors of widely deployed business software face added pressure to provide clear mitigation guidance quickly when critical flaws emerge before a patch is available.
Third-order effects
If repeated incidents concentrate around long-lived enterprise application deployments, vulnerability management will increasingly depend on compensating controls, segmentation, and detection rather than patching alone.
The pattern could accelerate a shift from treating core business software as a stable back-office asset to treating it as a continuously managed security boundary, though the eventual impact depends on the vulnerability’s confirmed scope and exploitability.
The trend: Critical flaws and breach claims involving entrenched enterprise platforms are making vendor response speed and customers’ interim defenses as consequential as the eventual patch.
🚨 ShinyHunters is exploiting an Oracle PeopleSoft vulnerability (CVE-2026-35273) as part of an extortion campaign targeting higher education. Read the full analysis, and get IOCs and remediation guidance to stay ahead of the threat: https://cloud.google.com/... [image]
🛑 ShinyHunters exploited an Oracle PeopleSoft zero-day to break into organizations, steal data, and demand payment. Mandiant says 100+ exposed endpoints were identified, with universities hit hardest. The flaw needs no login, no user click, just HTTP access. Full story: [image]
Unit 42 is tracking the active targeting of Oracle PeopleSoft servers by Bling Libra (aka #ShinyHunters). Our analysis reveals suspected exploitation of RCE flaw CVE-2026-35273 and primary targeting of the education sector since at least late May 2026. https://github.com/... [ima…
New from our our team at GTIG: #UNC6240 is back to targeting educational institutions in a new data theft extortion campaign. The activity targets Oracle's #PeopleSoft by exploiting Zero-Day CVE-2026-35273. Disable EMHub and check our blog for guidance. https://cloud.google.com/.…
🛡️ We added Oracle PeopleSoft Enterprise PeopleTools missing authentication for critical function vulnerability CVE-2026-35273 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec [image]
🚨 On 6/10/26, #Oracle published a security alert for CVE-2026-35273, a critical vuln. affecting PeopleSoft Enterprise PeopleTools. The campaign has been attributed to the ShinyHunters collective, well known for data theft and extortion. More in our blog: https://www.rapid7.com/..…
Google/Mandiant is urging organizations running Oracle PeopleSoft to take a number of actions to harden their systems following …
@lorenzofb Lorenzo Franceschi-Bicchierai on bluesky
NEW: Oracle is warning customers of an unpatched bug in its PeopleSoft software, which Google says is the flaw that cybercrime group ShinyHunters is exploiting in a mass hacking campaign. — Google said it notified more than 100 organizations worldwide that they had vulnerable P…