Skip to content
September 20, 2026
  • Facebook
  • Twitter
  • Linkedin
  • TiKTok
  • Youtube
  • Instagram
techtrib.com

TechTrib.com

World Best Tech & AI News By Experts

techEx Ad

Connect with Us

  • Facebook
  • Twitter
  • Linkedin
  • TiKTok
  • Youtube
  • Instagram
Primary Menu
  • HOME
  • NEWS
  • AI
  • CYBER SECURITY
  • APPS
  • MAGAZINE
  • TUTORIALS
  • REVIEWS
  • STORE
  • ABOUT US
  • ADVERTISE
Watch Video
  • Business
  • News
  • Science
  • Tech

Critical Oracle PeopleSoft Zero-Day Exploited: ShinyHunters Breach 100+ Companies in Mass Hacking Campaign

TechTrib.com June 12, 2026
Critical Oracle PeopleSoft Zero-Day Exploited

A major cybersecurity crisis is unfolding as Oracle has issued an emergency warning about a critical zero-day vulnerability in its PeopleSoft enterprise software  a flaw that the notorious hacking group ShinyHunters has already weaponized to breach more than 100 organizations worldwide. The attack, confirmed by Google’s Mandiant security unit, represents one of the most significant enterprise software breaches of 2026.

What Is the Oracle PeopleSoft Zero-Day?

Oracle’s PeopleSoft is widely used by large corporations, universities, and government agencies to manage payroll, human resources, and financial operations. The vulnerability, tracked as CVE-2026-35273, allows attackers to exploit PeopleSoft servers over the internet without any authentication  meaning no password or credentials are required to gain access. Oracle published a security advisory on Thursday, June 11, 2026, but has not yet released a patch at the time of writing.

The company is urging all PeopleSoft customers to apply available mitigations immediately while a full patch is being developed.

ShinyHunters: The Gang Behind the Attack

ShinyHunters is a well-known cybercrime group with a history of large-scale data theft operations. In this campaign, the group identified the zero-day vulnerability and systematically targeted organizations running vulnerable PeopleSoft servers. A ShinyHunters member told TechCrunch that the gang compromised companies by exploiting the unpatched flaw  a classic zero-day attack where the vendor has no time to fix the bug before it is discovered and exploited in the wild.

The group’s modus operandi is to steal sensitive corporate or customer data and then threaten to release it publicly unless victims pay a ransom. In previous campaigns, ShinyHunters targeted companies using Salesforce, Gainsight, and education technology giant Instructure the latter of which paid the hackers after being breached twice.

Education Sector Hit Hardest

According to Mandiant, approximately two-thirds of the 100+ affected organizations are in higher education  universities and colleges across the United States. The hackers claimed to have stolen “hundreds of thousands of student records” containing full names, home addresses, phone numbers, emails, dates of birth, gender, ethnicity, enrollment status, GPA, major, and student IDs.

Google’s Mandiant unit has notified more than 100 global organizations of their potential exposure and is working to help them restrict access to vulnerable systems. The cybersecurity firm confirmed that while some organizations successfully blocked the attack or remediated the vulnerability, others experienced full compromise, with stolen data already published on ShinyHunters’ data leak website.

Novo Nordisk Also Hit

In a related development, pharmaceutical giant Novo Nordisk flagged a separate cyberattack on June 11, 2026, reporting that patient data from some clinical trials was breached. While not directly linked to the Oracle zero-day, the incident underscores the escalating threat landscape facing enterprises across all sectors.

What Organizations Should Do Now

  • Apply Oracle’s recommended mitigations for PeopleSoft immediately
  • Review server logs for the indicator of compromise IP: 51.159.98.241
  • Isolate vulnerable PeopleSoft instances from public internet access
  • Monitor for unauthorized data access or exfiltration
  • Contact Mandiant or your incident response team if compromise is suspected

Industry Impact

This breach highlights a growing trend of supply-chain and enterprise software attacks, where a single vulnerability in widely-used software can cascade into hundreds of simultaneous breaches. The Oracle PeopleSoft zero-day is a stark reminder that even the most established enterprise software vendors are not immune to critical security flaws.

For quality tech news, professional analysis, insights, and the latest updates on technology, follow TechTrib.com. Stay connected and join our fast-growing community.


TechTrib.com is a leading technology news platform providing comprehensive coverage and analysis of tech news, cybersecurity, artificial intelligence, and emerging technology. Visit techtrib.com. 

Contact Information: Email: news@techtrib.com or for adverts placement adverts@techtrib.com

Related Posts

  • India has extended its anti spam regime to require caller ID and call management apps to share users’ spam reports with telecom operators
  • Google’s new ‘CC’ is an AI agent that helps families run their households
  • Meta’s Muse hits Mac, letting the AI take actions on your computer
  • Anthropic and OpenAI want to embed safety evaluators. Will they really be independent?
  • Musk’s long-time backer is giving SpaceX stock to its investors

About The Author

TechTrib.com

See author's posts

Post navigation

Previous: WWDC 2026 Wrap-Up: Apple Unveils iOS 27, Next-Gen Siri AI Powered by Gemini, and Apple Intelligence 2.0
Next: Meta’s AI Chatbot Exploited to Hijack Instagram Accounts Millions of Users at Risk

Best Tech Review of the Week

Trending News

India has extended its anti spam regime to require caller ID and call management apps to share users’ spam reports with telecom operators unnamed 1
  • AI Updates
  • Business
  • News
  • Science
  • Tech

India has extended its anti spam regime to require caller ID and call management apps to share users’ spam reports with telecom operators

September 19, 2026
Google’s new ‘CC’ is an AI agent that helps families run their households EU Imposes Record €2.95 Billion Fine on Google for Anticompetitive Advertising Technology Practices 2
  • AI Updates
  • Business
  • News
  • Science
  • Tech

Google’s new ‘CC’ is an AI agent that helps families run their households

September 19, 2026
Meta’s Muse hits Mac, letting the AI take actions on your computer Inside Meta's 'Soul-Crushing Gulag' 6,500 Engineers Revolt 3
  • AI Updates
  • Business
  • News
  • Science
  • Tech

Meta’s Muse hits Mac, letting the AI take actions on your computer

September 19, 2026
Anthropic and OpenAI want to embed safety evaluators. Will they really be independent? OpenAI-v-Anthropic-Superbowl-Ads 4
  • AI Updates
  • Business
  • News
  • Science
  • Tech

Anthropic and OpenAI want to embed safety evaluators. Will they really be independent?

September 17, 2026
Musk’s long-time backer is giving SpaceX stock to its investors Elon Musk Demands Up to $134 Billion from OpenAI in Explosive Legal Battle 5
  • AI Updates
  • Business
  • News
  • Science
  • Tech

Musk’s long-time backer is giving SpaceX stock to its investors

September 17, 2026

Connect with Us

  • Facebook
  • Twitter
  • Linkedin
  • TiKTok
  • Youtube
  • Instagram

Quick Links

  • NEWS
  • CYBER SECURITY
  • AI
  • REVIEWS
  • STORE
  • ABOUT US
  • ADVERTISE

Gallery

technology-joystick-controller-youth-gadget-playing-948574-pxhere.com
IMG_4402
tech-technology-vr-vr-headset-headset-boy-1629858-pxhere.com
IMG_4404

About US

TechTrib.com

Welcome to TechTrib.com, your go-to destination for the latest information in technology, AI, and innovation. It's a community-driven platform founded with a mission to bring expert-driven insights to our global audience and community. TechTrib.com delivers timely, accurate, and engaging news to AI enthusiasts, tech professionals, non-tech enthusiasts, and businesses alike.

Experts Tech Reviews
Tech Geeks Store

Contact us:

News@techtrib.com, Adverts@techtrib.com

  • Facebook
  • Twitter
  • Linkedin
  • TiKTok
  • Youtube
  • Instagram
Copyright © 2026 All Rights Reserved. TechTrib.com
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}