CRITICAL ⚡ MUST-KNOW
Nissan, NAIC Breached via Oracle PeopleSoft Zero-Day, ShinyHunters Campaign
Nissan disclosed a data breach affecting current and former employees after attackers exploited an Oracle PeopleSoft zero-day vulnerability, part of a wider campaign linked to the ShinyHunters extortion group that reportedly targeted around 100 organizations. The National Association of Insurance Commissioners (NAIC) separately confirmed the same campaign stole data from its PeopleSoft instance, though it says only public, outdated, or configuration data was taken. Only a handful of the targeted organizations have confirmed breaches so far. Organizations running Oracle PeopleSoft should verify patch status and review for indicators tied to the ShinyHunters campaign.