{"id":350790,"date":"2026-06-14T17:33:31","date_gmt":"2026-06-14T12:03:31","guid":{"rendered":"https:\/\/ebiztoday.news\/?p=350790"},"modified":"2026-06-14T17:33:31","modified_gmt":"2026-06-14T12:03:31","slug":"peoplesoft-0-day-affecting-tons-of-of-organizations-steals-gigabytes-of-information","status":"publish","type":"post","link":"https:\/\/ebiztoday.news\/index.php\/2026\/06\/14\/peoplesoft-0-day-affecting-tons-of-of-organizations-steals-gigabytes-of-information\/","title":{"rendered":"PeopleSoft 0-day affecting tons of of organizations steals gigabytes of information"},"content":{"rendered":"<p><\/p>\n<div>\n<p>\u201cWhile several organizations successfully blocked the activity or remediated the vulnerabilities, others experienced compromise, leading to stolen data being published on the ShinyHunters DLS,\u201d Mandiant said. (DLS is brief for data leak site.)<\/p>\n<p>An evaluation of a bash script left within the staging environment shows the attackers performed reconnaissance on compromised organizations, including mapping the PeopleSoft configurations, viewing process scheduler, and WebLogic server XML configurations. Eventually, the threat actors established an outbound SSH connection to 176.120.22.24, the IP address hosting ShinyHunters\u2019 DLS. The stolen data was first compressed using the zstd tool. The DLS claimed to have recovered 48GB of information from a single victim.<\/p>\n<figure class=\"ars-wp-img-shortcode id-2159197 align-none\">\n<div>\n<div class=\"ars-lightbox\">\n<div class=\"ars-lightbox-item\">\n            <a class=\"cursor-zoom-in\" data-pswp-width=\"1700\" data-pswp-height=\"756\" data-pswp-srcset=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/06\/shinyhunters-dls.png 1700w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/06\/shinyhunters-dls-640x285.png 640w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/06\/shinyhunters-dls-1024x455.png 1024w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/06\/shinyhunters-dls-768x342.png 768w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/06\/shinyhunters-dls-1536x683.png 1536w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/06\/shinyhunters-dls-980x436.png 980w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/06\/shinyhunters-dls-1440x640.png 1440w\" data-cropped=\"false\" href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/06\/shinyhunters-dls.png\" target=\"_blank\"><\/p>\n<p>            <\/a><\/p>\n<div class=\"pswp-caption-content\" id=\"caption-2159197\">\n              A partially redacted section of the ShinyHunters\u2019 DLS.<\/p>\n<p>\n                  Credit:<br \/>\n                                      Mandiant\n                                  <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div><figcaption>\n<div class=\"caption font-impact dusk:text-gray-300 mb-4 mt-2 inline-flex flex-row items-stretch gap-1 text-base leading-tight text-gray-400 dark:text-gray-300\">\n<p>\n      A partially redacted section of the ShinyHunters\u2019 DLS.<\/p>\n<p>              <span class=\"caption-credit mt-2 text-xs\"><br \/>\n          Credit:<\/p>\n<p>          Mandiant<\/p>\n<p>                  <\/span>\n          <\/p>\n<\/p><\/div>\n<\/figcaption><\/figure>\n<p>ShinyHunters has been energetic since not less than 2019. Over the past several years, it has executed scores of hacks against a few of the world\u2019s largest corporations, affecting hundreds of thousands of individuals downstream. A small sample of victims includes Ticketmaster (through the breach of Snowflake, which hosted the information), Spain\u2019s biggest bank, Santander, and Salesforce (and, through it, Google and, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/google-suffers-data-breach-in-ongoing-salesforce-data-theft-attacks\/\">reportedly<\/a>, many other corporations). ShinyHunters uses various techniques to realize initial access, including exploiting cloud misconfigurations and software vulnerabilities, stealing OAuth tokens, supply chain attacks, voice phishing, and other types of social engineering.<\/p>\n<p>Mandiant and <a href=\"https:\/\/www.rapid7.com\/blog\/post\/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273\/\">Rapid7<\/a> are providing detailed indicators of compromise. Also they are advising PeopleSoft customers on the steps they need to take immediately. Given ShinyHunters\u2019 success rate, all PeopleSoft users would do well to heed the calls.<\/p>\n<\/p><\/div>\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u201cWhile several organizations successfully blocked the activity or remediated the vulnerabilities, others experienced compromise, leading to stolen data being published on the ShinyHunters DLS,\u201d Mandiant said. (DLS is brief for data leak site.) An evaluation of a bash script left within the staging environment shows the attackers performed reconnaissance on compromised organizations, including mapping the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":350791,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[24170,24460,1479,52831,7144,7958,52830,12720],"class_list":["post-350790","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-0day","tag-affecting","tag-data","tag-gigabytes","tag-hundreds","tag-organizations","tag-peoplesoft","tag-steals"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/posts\/350790","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/comments?post=350790"}],"version-history":[{"count":2,"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/posts\/350790\/revisions"}],"predecessor-version":[{"id":350793,"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/posts\/350790\/revisions\/350793"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/media\/350791"}],"wp:attachment":[{"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/media?parent=350790"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/categories?post=350790"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/tags?post=350790"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}