Oracle warns of security bug that hackers abused to breach 100+ companies
techcrunch.com Jun 12, 2026

Oracle warns of security bug that hackers abused to breach 100+ companies

AI-summarised brief · reviewed before publication

Oracle has warned its corporate customers about a critical-rated vulnerability in its PeopleSoft software, which has been exploited by hackers to breach over 100 companies. The bug, known as a zero-day, can be exploited over the internet without authentication, and Oracle has not yet released a patch. Mandiant, a Google-owned security unit, has notified over 100 global organizations about the vulnerability and recommended that customers apply mitigations to prevent exploitation.

💡 Why It Matters

  • · The ShinyHunters hacking group's exploitation of the PeopleSoft vulnerability highlights a disturbing trend of targeting organizations with shared vulnerable software, putting hundreds of thousands of student records at risk.
  • · The group's tactics of stealing data and threatening to release it unless a ransom is paid have already led to a company paying hackers, underscoring the need for swift action to prevent further breaches.