Threat Actors Exploit Oracle PeopleSoft
Coverage from The National CIO Review, SecurityWeek, and others

Threat actors exploited an Oracle PeopleSoft PeopleTools zero-day, tracked as CVE-2026-35273, to access sensitive personnel records held by enterprise HR and payroll systems.
Nissan reported potential exposure of employee and dependent information across several countries, while reporting linked the broader campaign to ShinyHunters and identified additional affected organizations. The incidents show how compromise of HR platforms can expose identity, payroll, tax, banking, and benefits data, prompting containment measures, vendor coordination, and credit or identity monitoring for affected individuals.
The main update is a modest reframing of the campaign: reporting now more explicitly links the PeopleSoft thefts to ShinyHunters and adds that some organizations have begun tightening access controls and identity checks. The Nissan and Kubota incidents are otherwise broadly consistent, with the Kubota case still presented as separate rather than connected.
The update adds a concrete zero-day attribution and timeline for the Oracle PeopleSoft campaign, plus broader claims about scale and remediation at Nissan. It also sharpens the Kubota disclosure with more specific exposed data types and timing.
