Oracle rushes emergency patch for critical PeopleSoft zero-day exploited in mass data-theft attacks
Oracle $ORCL has issued an emergency, out-of-band patch for a critical PeopleSoft PeopleTools flaw rated 9.8 out of 10 that lets an unauthenticated attacker run code on the server remotely. Researchers say it was exploited as a zero-day for about two weeks before the fix, and the
Oracle $ORCL has issued an emergency, out-of-band patch for a critical PeopleSoft PeopleTools flaw rated 9.8 out of 10 that lets an unauthenticated attacker run code on the server remotely. Researchers say it was exploited as a zero-day for about two weeks before the fix, and the ShinyHunters group claims it breached more than 100 organizations, including universities. Oracle says only PeopleTools 8.61 and 8.62 are affected; apply the patch and review logs for unauthorized access.