Back to all lessons
Awareness Lessons
3 months ago

Zero-Day in Oracle PeopleSoft Enables ShinyHunters Breach of NAIC

ShinyHunters exploited a zero-day vulnerability (CVE-2026-35273) in an Oracle PeopleSoft server to breach the NAIC, underscoring the severe risk posed by unpatched or unmitigated zero-days in enterprise software. While NAIC reports that only publicly available data, outdated logs, and configuration files were stolen, the exposure of configuration files is itself a significant concern as these can reveal system architecture, credentials, or pathways for deeper intrusion. The fact that this campaign has hit over 100 organizations highlights how a single unpatched vulnerability in widely-used enterprise software can be weaponized at scale. Organizations must treat internet-facing enterprise applications as high-priority targets and implement compensating controls when patches are not immediately available.

Tactical Insight

Immediate actions

  • Apply vendor-supplied patches or mitigations for CVE-2026-35273 on all Oracle PeopleSoft instances immediately.
  • Audit and restrict external internet exposure of PeopleSoft and other ERP systems behind VPNs or application firewalls.
  • Review and purge unnecessary configuration files, outdated logs, and sensitive artifacts stored on internet-facing servers.

Detection measures

  • Deploy continuous vulnerability scanning focused on internet-facing assets to identify zero-day and newly disclosed CVEs within hours of publication.
  • Implement real-time alerting for anomalous access patterns or data exfiltration attempts on ERP systems.
  • Subscribe to Oracle's Critical Patch Update advisories and threat intelligence feeds tracking groups like ShinyHunters.

Long-term improvements

  • Establish a formal zero-day response playbook that defines compensating controls (e.g., WAF rules, network isolation) when patches are unavailable.
  • Implement strict network segmentation to isolate ERP systems from other critical infrastructure and limit lateral movement.
  • Conduct regular configuration audits to ensure sensitive files, credentials, and system details are never stored in web-accessible directories.