---
title: "Oracle mitigates PeopleSoft zero-day exploited in data theft attacks"
url: https://daily.dev/posts/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks-ts5qbro18
source_url: https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks
type: article
source: "BleepingComputer"
published: 2026-06-11T19:41:11.831Z
updated: 2026-06-11T19:41:37.084Z
tags: ["data-privacy", "zero-day"]
reading_time: 3
upvotes: 1
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Oracle mitigates PeopleSoft zero-day exploited in data theft attacks

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 1 upvotes · 0 comments

## Summary

Oracle has issued an emergency mitigation for CVE-2026-35273, a critical zero-day vulnerability in PeopleSoft PeopleTools (versions 8.61 and 8.62) with a CVSS score of 9.8 that enables unauthenticated remote code execution. The flaw is being actively exploited by the ShinyHunters extortion gang, who have reportedly breached over 300 PeopleSoft instances across more than 100 organizations to steal data and demand ransoms. Mandiant CTO Charles Carmakal confirmed the active exploitation. ShinyHunters claims to use a 'gadget chain' of old and zero-day vulnerabilities. Administrators are urged to apply Oracle's emergency mitigations and check logs for connections from a set of known attacker IP addresses.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks>

## Similar posts on daily.dev

- [Oracle warns of security bug that hackers abused to breach 100\+ companies](https://daily.dev/posts/oracle-warns-of-security-bug-that-hackers-abused-to-breach-100-companies-vgnqoxr03) · TechCrunch · 0 upvotes · 0 comments
- [Active Exploitation of Oracle PeopleSoft Zero-Day \(CVE-2026-35273\)](https://daily.dev/posts/active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273--tyz4demr3) · Rapid7 Cybersecurity Blog · 0 upvotes · 0 comments
- [Oracle PeopleSoft zero‑day fuels ShinyHunters extortion spree](https://daily.dev/posts/oracle-peoplesoft-zero-day-fuels-shinyhunters-extortion-spree-fytdsgnoy) · CSO Online · 0 upvotes · 0 comments
- [PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data](https://daily.dev/posts/peoplesoft-0-day-affecting-hundreds-of-organizations-steals-gigabytes-of-data-rbusirs36) · Ars Technica · 0 upvotes · 0 comments
- [ShinyHunters breached 100\+ companies through an unpatched Oracle PeopleSoft zero-day](https://daily.dev/posts/shinyhunters-breached-100-companies-through-an-unpatched-oracle-peoplesoft-zero-day-n7snkx2k0) · The Next Web · 0 upvotes · 0 comments

---

Tags: [#data-privacy](https://daily.dev/tags/data-privacy), [#zero-day](https://daily.dev/tags/zero-day)

[View this post on daily.dev](https://daily.dev/posts/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks-ts5qbro18)
