VulnerabilityBleeping Computer
9.8 — CRITICAL
NAIC says public data stolen in ShinyHunters' PeopleSoft breach
The National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, and configuration files after breaching its systems by exploiting a zero-day vulnerability in an Oracle PeopleSoft server. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
The ShinyHunters extortion group exploited a zero-day vulnerability in Oracle PeopleSoft (CVE-2026-35273) to breach the NAIC's systems, stealing publicly available data and configuration files, with no personally identifiable information or financial data exposed.
⚙️Technical Details
Affected Systems
Oracle PeopleSoft Enterprise PeopleTools
Attack Vectors
NETWORK
💥Impact Assessment
Severity: critical
🛡️Recommended Actions
1Implement additional defenses to prevent future attacks
2Monitor for suspicious activity and implement incident response plans
3Regularly update software and systems with the latest security patches
📦Affected Products
Oracle Peoplesoft Enterprise Peopletools
🔐NVD Verified DataVERIFIED
CVE-2026-35273 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-306
Affected Products (CPE)
Oracle Peoplesoft Enterprise Peopletools
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
