Find notable cyber news and cases, enriched with sources, timelines, and signals.

Oracle PeopleSoft broad zero-day exploitation campaign

Exploitation Wave
First reported
Last updated
Happening score
H score 82
2 unique sources, 2 articles

Summary

Hide ▲

A broad PeopleSoft zero-day exploitation campaign exposed multiple organizations to compromise after attackers abused a previously unknown Oracle PeopleSoft vulnerability. The wave widened risk for organizations running the platform, including internal reporting environments. NAIC tied its own breach to the same campaign after an unauthorized actor reached part of its PeopleSoft environment.

Related Happenings

Oracle E-Business Suite May 2026 Critical Security Patch Update (CVE-2026-46817)

Security Patch Release
H score53 First: 29.06.2026 16:46 Last: 29.06.2026 16:46 Sources 1

About this happening: Oracle's May 2026 Critical Security Patch Update addressed CVE-2026-46817 in Oracle E-Business Suite, a critical flaw in Oracle Payments that could let an...

Oracle E-Business Suite unauth HTTP takeover security flaw (CVE-2026-46817)

Vulnerability
H score52 First: 29.06.2026 16:46 Last: 29.06.2026 16:46 Sources 1

About this happening: Oracle E-Business Suite CVE-2026-46817 is under active exploitation, putting Oracle Payments deployments at takeover risk. The flaw allows unauthenticated HTTP a...

US National Association of Insurance Commissioners (NAIC) hit by network compromise

Incident
H score80 First: 29.06.2026 13:00 Last: 29.06.2026 13:00 Sources 1

How related: The US National Association of Insurance Commissioners (NAIC) has suffered a security breach that has exposed US citizens’ credit rating data.

About this happening: NAIC disclosed a security breach that exposed US citizens’ credit rating data and briefly disrupted operations tied to Oracle PeopleSoft. The breach was detected o...

Oracle PeopleSoft PeopleTools zero-day RCE (CVE-2026-35273)

Vulnerability
H score58 First: 11.06.2026 22:39 Last: 11.06.2026 22:39 Sources 1

How related: an unauthorized actor gained access to “a portion” of its environment through the exploitation of a zero-day vulnerability in Oracle PeopleSoft, which NAIC uses for internal financial reporting purposes.

About this happening: Oracle PeopleSoft PeopleTools CVE-2026-35273 is a critical zero-day RCE affecting PeopleSoft Enterprise PeopleTools 8.61 and 8.62. Oracle released emergency mitigati...

Latest development: 29.06.2026 23:40

Nissan says it suffered a data breach affecting current and former employees after attackers exploited an Oracle PeopleSoft zero-day associated with CVE-2026-35273. Oracle informed Nissan that personnel records of hundreds of companies may have been obtained and that Nissan was specifically targeted, with potentially exposed data including contact details, banking information, Social Security numbers, Social Insurance Numbers, National Identification Numbers, financial and tax information, and dependent and beneficiary data for employees in the United States, Canada, Mexico, and Brazil.

University of Nottingham hit by cyberattack

Incident
H score68 First: 11.06.2026 10:27 Last: 11.06.2026 10:27 Sources 1

About this happening: The University of Nottingham said a well-known cybercriminal group accessed its student record system, exposing a significant amount of data affecting current students and...

Timeline

  1. 29.06.2026 13:00 1 articles · 16d ago

    Unauthorized actor exploits Oracle PeopleSoft zero-day against NAIC

    Exploitation Observed

    The US National Association of Insurance Commissioners detected a breach in which an unauthorized actor gained access to a portion of its Oracle PeopleSoft environment by exploiting a zero-day vulnerability used for internal financial reporting purposes.

    Show sources
  2. 29.06.2026 13:00 3 articles · 16d ago

    NAIC publicly discloses a breach exposing credit rating data

    Initial Disclosure

    The US National Association of Insurance Commissioners disclosed the breach to the public, saying the incident exposed US citizens’ credit rating data and that the event had been detected earlier in June.

    Show sources
  3. 29.06.2026 13:00 1 articles · 16d ago

    NAIC restores most operations after PeopleSoft breach, with online invoice payments still unavailable

    Mitigation Patch Update

    NAIC said it promptly contained the breach, blocked the attacker’s access, engaged outside counsel and cybersecurity experts, coordinated with the FBI, and returned most operations to normal while online invoice payment via PeopleSoft remained unavailable.

    Show sources