Oracle warns of critical PeopleSoft zero‑day

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Oracle issued a security advisory warning that a critical PeopleSoft vulnerability can be exploited over the internet without authentication.
- ShinyHunters claimed to have breached more than 100 organizations using PeopleSoft, including universities, stealing extensive student records.
- Mandiant confirmed the flaw is the same bug ShinyHunters is abusing and notified over 100 global organizations, about two‑thirds of which are higher‑education institutions.
- Oracle has not released a patch for the vulnerability, instead recommending mitigations for customers.
- PeopleSoft vulnerability is a zero‑day, meaning Oracle had no time to fix it before exploitation.
- ShinyHunters previously targeted other platforms such as Salesforce, Gainsight, and Instructure’s Canvas, using ransom threats to avoid data release.
Why it matters: Higher‑education institutions and other PeopleSoft users face immediate data‑theft risk because the unauthenticated zero‑day remains unpatched, forcing them to apply mitigations while ShinyHunters profits from stolen records and ransom threats. The breach also exposes personal details of thousands of students, increasing the potential for identity theft and legal liability for the affected schools.



