VulnerabilityBleeping Computer
9.8 — CRITICAL
Nissan discloses employee data breach linked to Oracle zero-day attacks
Nissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Nissan suffered a data breach due to exploitation of an Oracle PeopleSoft zero-day vulnerability, linked to ShinyHunters extortion group, impacting hundreds of companies including current and former employees in the United States, Canada, Mexico, and Brazil.
⚙️Technical Details
Affected Systems
Oracle PeopleSoft
Attack Vectors
NETWORK
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Current and former Nissan employees in the United States, Canada, Mexico, and Brazil
🛡️Recommended Actions
1Implement additional identity verification measures for payroll requests
2Restrict access to employee pay slips and direct deposit changes to company network computers or secured VPN connections
3Monitor credit reports and dark web for potential data leaks
📦Affected Products
Oracle Peoplesoft Enterprise PeopletoolsOracle PeopleSoft Enterprise PeopleTools
🔐NVD Verified DataVERIFIED
CVE-2026-35273 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-306
Affected Products (CPE)
Oracle Peoplesoft Enterprise Peopletools
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
