In June 2026, Google's threat teams confirmed that CVE-2026-35273, a remote code execution flaw in Oracle PeopleSoft, had been exploited as a zero-day. The extortion group ShinyHunters used it to break into more than 100 organizations worldwide, and 68 percent of the victims were in higher education. Because it was a zero-day, there was no patch to apply while the attacks were happening; Oracle only shipped the fix in an out-of-band update in June.
PeopleSoft runs a lot of HR, finance, and student records, so a hole like this hands attackers exactly the kind of data that fuels extortion.
Most small businesses don't run PeopleSoft, but the pattern is the one that matters: internet-facing business software is a favorite target, and "we'll patch eventually" is a losing plan. Keep an inventory of any admin panels or vendor portals exposed to the internet, subscribe to their security advisories, and apply critical patches in days, not months. Where you can, put that software behind a VPN or IP allowlist so it isn't open to the whole world.
Further reading: original source ↗
Want this handled for you?
This is exactly the kind of thing our website security work takes off your plate. Start with a free, no-pressure look at your site.
Come aboard