The images in this article were generated with artificial intelligence. How we publish
Oracle has issued a safety alert for critical vulnerability CVE-2026-35273 in PeopreSoft PeopleTools, a fault with a CVSS score of 9.8 that allows remote code execution without authentication. Technical gravity (CERs without authentication) and Oracle's confirmation of the affected versions - PeopleTools 8.61 and 8.62 - make it an immediate risk to any organization that runs exposed instances of PeopleSoft. Oracle has published emergency mitigation while preparing a permanent patch; it is recommended that they be consulted and applied as soon as possible in affected environments: Oracle Security Alerts.
Public reports relate the active exploitation of this zero-day with the extortion group known as ShinyHunters, which a priori would have used a "chain of gadgets" combining old and this zero-day exploits to extract data from hundreds of instances. If the information available is correct, there is a component of massive data theft and subsequent rescue pressure that turns this failure into a hybrid threat: technical and business. Initial coverage and independent analysis have documented the nature and extent of incidents; it is useful to follow open technical sources to correlate indicators: BleepingComputer.

In immediate practice, there is a clear chain of priorities: first, minimize the attack surface; second, seek compromise indicators; third, contain and remedy. As urgent and concrete measures, apply the provisional mitigation published by Oracle, disconnect or restrict public access to PeopleSoft instances, and close administrative interfaces exposed to the Internet through firewall rules or zero-confidence access policies. These actions reduce the exposure window until the patch is available.
The investigation of incidents must include an active search for historical and contemporary commitments. Analyze access and network log for suspicious connections, in particular from the IP that have been reported in relation to these campaigns (e.g., ranges cited by researchers), and track changes in accounts, creation of webshells or side movements to databases and storage systems. If abnormal activity is detected, isolate committed instances and preserve evidence for forensic analysis.
In addition to technical containment, there are essential operational steps: immediate rotation of credentials with privileges over PeopleSoft, review and revocation of committed accounts and keys, verification of backups integrity and recovery plans, and internal communication to activate your incident response process. Do not wait for the final patch to act: the combination of temporary mitigation, network segmentation and active monitoring reduces the probability of data loss.
For organizations with third-party suppliers or integrations, the failure also poses a supply chain risk: PeopleSoft usually contains sensitive data on payroll, human resources and finance. It is critical to notify the business units concerned, to assess the regulatory impact of exfiltration of identifiable personal information (PII) and to prepare communications to customers and authorities according to their legal and compliance obligations. Maintain traceability of actions and decisions for audit and legal response.

At the strategic level, this incident reinforces known lessons: the need to minimize public exposures of critical business systems, prioritizing software patches that manage sensitive data and investing in early detection. Adopt network segmentation, multifactor authentication for administrative access, regular gap simulation tests and detection rules focused on abnormal behavior in your EDR / SIEM. These controls reduce both the probability and impact of similar incidents.
For technical teams that need additional references: check Oracle's official alerts and mitigation and review the vulnerability catalogues exploited by real actors to prioritize corrections in your asset inventory. The catalogue of vulnerabilities exploited by real US government actors. UU offers context on prioritizing patches and adopting mitigation: CISA KEV. Keep an eye on Oracle's final patch bulletins and coordinate with your incident response team for mitigation testing in controlled environments prior to their mass deployment.
If your organization uses PeopleSoft, act now: apply mitigation, strengthen access controls, monitor logs (including IP reported by researchers), and prepare the response and reporting process are steps that will make the difference between a contending incident and a data leak with long legal and economic consequences.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...