Key takeaway: An unpatched PeopleSoft vulnerability is being exploited as a zero-day by extortionists; CISOs must scan their systems for indicators and prioritize Oracle patches.
An unpatched security vulnerability in PeopleSoft systems is being deliberately exploited by an extortion group to compromise multiple prominent organizations. The vulnerability is being treated as a zero-day because patches were not available in a timely manner.
According to Golem.de reporting by Steffen Zahn, a security vulnerability in PeopleSoft products is being systematically used by an organized extortion group against multiple prominent targets. The vulnerability affected unpatched systems at the time of the attacks, which is why it functioned de facto as a zero-day. Oracle, which develops PeopleSoft products, did not act proactively with security updates.
Attackers gained access to mission-critical systems through this vulnerability, causing significant operational disruptions particularly for organizations with direct dependence on PeopleSoft (HR, Payroll, Finance, Supply Chain). The extortion group used the access for data exfiltration followed by extortion. Names of affected organizations were partially made public.
Several areas of action emerge for CISOs: First, all PeopleSoft instances should be scanned for access by invalid users or suspicious API calls. Second, prioritization of Oracle security updates is essential. Third, a review of access controls on critical functions is recommended (particularly payroll and payment processes). Fourth, network segmentation measures should be reviewed to complicate lateral movement.
The case illustrates that extortion groups deliberately target known, long-term unpatched vulnerabilities in standard products. A purely patch-management strategy is insufficient; supplementary monitoring of application logs and immediate incident response plans are necessary.
Source: www.golem.de · Published July 13, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification through Lumi News Pipeline v1.7.3.