Key facts
- A zero-day vulnerability in PeopleSoft has been exploited, affecting hundreds of organizations.
- Stolen data has been published on the ShinyHunters data leak site.
- One victim reportedly lost 48GB of data.
- Attackers mapped PeopleSoft configurations and viewed server XML configurations.
- Mandiant and Rapid7 are advising PeopleSoft customers on remediation steps.
A zero-day vulnerability affecting PeopleSoft has been exploited by threat actors, leading to data breaches at hundreds of organizations. Mandiant reported that some compromised entities experienced data theft, with the stolen information subsequently published on the ShinyHunters data leak site (DLS).
