FeedVulnerabilityNAIC says public data stolen in ShinyHunters' PeopleSoft bre...
VulnerabilityBleeping Computer
9.8CRITICAL

NAIC says public data stolen in ShinyHunters' PeopleSoft breach

📅 29 June 2026 at 20:30 UTC📰 Bleeping ComputerView original source ↗
NAIC says public data stolen in ShinyHunters' PeopleSoft breach

The National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, and configuration files after breaching its systems by exploiting a zero-day vulnerability in an Oracle PeopleSoft server. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

The ShinyHunters extortion group exploited a zero-day vulnerability in Oracle PeopleSoft (CVE-2026-35273) to breach the NAIC's systems, stealing publicly available data and configuration files, with no personally identifiable information or financial data exposed.

⚙️Technical Details
Affected Systems
Oracle PeopleSoft Enterprise PeopleTools
Attack Vectors
NETWORK
💥Impact Assessment
Severity: critical
🛡️Recommended Actions
1Implement additional defenses to prevent future attacks
2Monitor for suspicious activity and implement incident response plans
3Regularly update software and systems with the latest security patches
📦Affected Products
Oracle Peoplesoft Enterprise Peopletools
🔐NVD Verified DataVERIFIED
CVE-2026-35273CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-306
Affected Products (CPE)
Oracle Peoplesoft Enterprise Peopletools

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed