CVE-2026-35273遭ShinyHunters连攻两周,百企PeopleSoft失守被勒索

AI导读

活跃勒索组织ShinyHunters利用Oracle PeopleSoft高危漏洞CVE-2026-35273(评分9.8)实施攻击,在Oracle披露前已持续利用超两周。该SSRF漏洞可被远程利用,攻击者借此以受控服务器向目标内网发起请求。Mandiant确认约百家客户遭入侵,至少一家被勒索付款以避免数据泄露;Oracle已发布临时缓解措施,完整补丁尚未发布。

AI Prism 智棱 - AI安全 分类封面图
One of the world’s most active ransomware groups exploited a critical vulnerability in Oracle’s PeopleSoft software suite and used it to target about 100 customers and extort at least one of them to pay up in exchange for not leaking stolen data, researchers said. The group, tracked as ShinyHunters, had been exploiting the PeopleSoft vulnerability for more than two weeks before Oracle flagged it. CVE-2026-35273, as the vulnerability is tracked, carries a severity rating of 9.8 out of 10, making the former zero-day one of the year’s most critical vulnerabilities to be exploited. Google’s Mandiant security team said it’s an SSRF (server-side request forgery), a vulnerability that allows attackers to send requests from a susceptible server to systems used by the targeted organization. Oracle said the SSRF is remotely exploitable, and the company has issued a stopgap mitigation but has yet to fully patch the flaw. Google has confirmed that victims are receiving extortion demands.Read full article Comments

内容声明

本文内容基于公开市场信息与媒体报道进行整理,部分观点来自社区讨论。如涉及事实性问题,欢迎通过 xurj005@163.com 与我们指正,我们将及时核实并更新。