Zero-Day in Oracle PeopleSoft Enables ShinyHunters Breach of NAIC
ShinyHunters exploited a zero-day vulnerability (CVE-2026-35273) in an Oracle PeopleSoft server to breach the NAIC, underscoring the severe risk posed by unpatched or unmitigated zero-days in enterprise software. While NAIC reports that only publicly available data, outdated logs, and configuration files were stolen, the exposure of configuration files is itself a significant concern as these can reveal system architecture, credentials, or pathways for deeper intrusion. The fact that this campaign has hit over 100 organizations highlights how a single unpatched vulnerability in widely-used enterprise software can be weaponized at scale. Organizations must treat internet-facing enterprise applications as high-priority targets and implement compensating controls when patches are not immediately available.
Tactical Insight
Immediate actions
- Apply vendor-supplied patches or mitigations for CVE-2026-35273 on all Oracle PeopleSoft instances immediately.
- Audit and restrict external internet exposure of PeopleSoft and other ERP systems behind VPNs or application firewalls.
- Review and purge unnecessary configuration files, outdated logs, and sensitive artifacts stored on internet-facing servers.
Detection measures
- Deploy continuous vulnerability scanning focused on internet-facing assets to identify zero-day and newly disclosed CVEs within hours of publication.
- Implement real-time alerting for anomalous access patterns or data exfiltration attempts on ERP systems.
- Subscribe to Oracle's Critical Patch Update advisories and threat intelligence feeds tracking groups like ShinyHunters.
Long-term improvements
- Establish a formal zero-day response playbook that defines compensating controls (e.g., WAF rules, network isolation) when patches are unavailable.
- Implement strict network segmentation to isolate ERP systems from other critical infrastructure and limit lateral movement.
- Conduct regular configuration audits to ensure sensitive files, credentials, and system details are never stored in web-accessible directories.