{"id":13962,"date":"2026-06-30T10:03:37","date_gmt":"2026-06-30T10:03:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/30\/nissan-confirms-data-breach-following-oracle-peoplesoft-0-day-attacks\/"},"modified":"2026-06-30T10:03:37","modified_gmt":"2026-06-30T10:03:37","slug":"nissan-confirms-data-breach-following-oracle-peoplesoft-0-day-attacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/30\/nissan-confirms-data-breach-following-oracle-peoplesoft-0-day-attacks\/","title":{"rendered":"Nissan Confirms Data Breach Following Oracle PeopleSoft 0-Day Attacks"},"content":{"rendered":"<p>    Nissan Confirms Data Breach Following Oracle PeopleSoft 0-Day Attacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">Nissan Americas has officially confirmed a data breach affecting current and former employees across four countries after threat actors exploited a critical zero-day vulnerability in Oracle PeopleSoft software, a campaign attributed to the ShinyHunters extortion group.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/cybersecuritynews.com\/oracle-peoplesoft-0-day-rce-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">The attack stems from CVE-2026-35273<\/a>, a CVSS 9.8-rated unauthenticated Server-Side Request Forgery (SSRF)-to-Remote Code Execution (RCE) vulnerability residing in the Updates Environment Management (PSEMHUB) component of Oracle PeopleSoft PeopleTools versions 8.61 and 8.62.<\/p>\n<p class=\"wp-block-paragraph\">The flaw requires no authentication, no user interaction, and is exploitable over plain HTTP, meaning any attacker with network reach to a vulnerable instance could achieve full remote code execution. Oracle issued an emergency out-of-band security patch on June 10, 2026, and the vulnerability was added to CISA\u2019s Known Exploited Vulnerabilities (KEV) catalog just two days later.<\/p>\n<p class=\"wp-block-paragraph\">Mandiant and Google\u2019s Threat Intelligence Group (GTIG) attribute the <a href=\"https:\/\/cybersecuritynews.com\/oracle-peoplesoft-0-day-rce-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">campaign to UNC6240 (ShinyHunters)<\/a>, a financially motivated cybercrime collective also tracked as Bling Libra.<\/p>\n<p class=\"wp-block-paragraph\">Exploitation was observed as early as\u00a0May 27, 2026,\u00a0more than two weeks before Oracle\u2019s advisory, with the group compromising over\u00a0300 PeopleSoft instances across 100+ organizations worldwide\u00a0using automated attack scripts.<\/p>\n<h2 id=\"h-nissan-confirms-data-breach\" class=\"wp-block-heading\"><strong>Nissan Confirms Data Breach<\/strong><\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/oag.ca.gov\/ecrime\/databreach\/reports\/sb24-625558\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According to breach notifications filed<\/a> with the California Attorney General\u2019s Office, Nissan Americas confirmed it was specifically singled out within the broader campaign. The breach window spans May 27 to June 9, 2026, and potentially exposed sensitive employee data including:<\/p>\n<ul class=\"wp-block-list\">\n<li>Contact and banking information<\/li>\n<li>Social Security Numbers (SSN), Social Insurance Numbers (SIN), and National Identification Numbers<\/li>\n<li>Financial and tax data<\/li>\n<li>Dependent and beneficiary information<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">The incident is believed to impact current and former Nissan employees in the United States, Canada, Mexico, and Brazil.<\/p>\n<p class=\"wp-block-paragraph\">Nissan activated its incident response protocols immediately upon notification, engaging external cybersecurity specialists and cooperating with law enforcement authorities.<\/p>\n<p class=\"wp-block-paragraph\">As a containment measure, the company restricted payroll system access, including pay slip viewing and direct deposit changes, to corporate network computers or secure VPN connections, with additional identity authentication layers implemented before processing payroll requests. Nissan is also arranging free credit and dark web monitoring services for affected individuals where available.<\/p>\n<p class=\"wp-block-paragraph\">Mandiant\u2019s analysis reveals that ShinyHunters deployed MeshCentral remote management agents on compromised hosts, disguising them as legitimate Microsoft Azure services (e.g., <code>meshagent64-azure-ops.exe<\/code>) with C2 communications routed to <code>wss:\/\/azurenetfiles[.]net:443\/agent.ashx<\/code>.<\/p>\n<p class=\"wp-block-paragraph\">Post-exploitation activity included internal PeopleSoft configuration reconnaissance, lateral movement scripting, and data exfiltration using zstd compression. Compromised servers were marked with a ransom note file named <code>README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT<\/code>.<\/p>\n<h2 id=\"h-key-indicators-of-compromise-iocs\" class=\"wp-block-heading\"><strong>Key Indicators of Compromise (IOCs)<\/strong><\/h2>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Type<\/th>\n<th>Indicator<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>IP<\/td>\n<td><code>142.11.200[.]186\u2013190<\/code><\/td>\n<td>Staging\/C2 infrastructure<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td><code>azurenetfiles[.]net<\/code><\/td>\n<td>C2 masquerading as Azure<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td><code>f02a924c9ff92a8780ce812511341182...<\/code><\/td>\n<td><code>meshagent64-azure-ops.exe<\/code><\/td>\n<\/tr>\n<tr>\n<td>URL Path<\/td>\n<td><code>\/PSEMHUB\/hub<\/code><\/td>\n<td>Exploitation endpoint<\/td>\n<\/tr>\n<tr>\n<td>URL Path<\/td>\n<td><code>\/PSIGW\/HttpListeningConnector<\/code><\/td>\n<td>SSRF exploitation endpoint<\/td>\n<\/tr>\n<tr>\n<td>File<\/td>\n<td><code>README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT<\/code><\/td>\n<td>Extortion marker<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 id=\"h-mitigations\" class=\"wp-block-heading\"><strong>Mitigations<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Organizations running PeopleTools 8.61 or 8.62 should treat patching as an emergency priority. Beyond patching, Rapid7 and Mandiant recommend:<\/p>\n<ul class=\"wp-block-list\">\n<li>Disable or restrict the PSEMHUB service and block external access to <code>\/PSEMHUB\/*<\/code> and <code>\/PSIGW\/HttpListeningConnector<\/code> at the network perimeter<\/li>\n<li>Monitor outbound SMB traffic (TCP\/445) from PeopleSoft servers for external NetNTLM hash capture attempts<\/li>\n<li>Hunt for compromise indicators even post-patching, given exploitation activity predates Oracle\u2019s advisory by two weeks<\/li>\n<li>Rotate all credentials accessible from potentially compromised PeopleSoft instances<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">This marks the second CVSS 9.8 Oracle ERP zero-day exploited in under eight months, following Cl0p\u2019s abuse of CVE-2025-61882 in Oracle E-Business Suite beginning in August 2025 \u2014 a pattern that signals ERP platforms have become primary industrialized targets for organized extortion operations.<\/p>\n<p class=\"has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 87%,rgb(169,184,195) 100%)\"><strong>\u00a0Strengthen Your SOC by Accelerating Threat Detection &amp; Rapid Investigations.\u00a0-&gt; <a href=\"https:\/\/any.run\/enterprise\/?utm_source=csn&amp;utm_medium=links&amp;utm_campaign=sandbox&amp;utm_content=enterprise&amp;utm_term=0626#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Integrate ANY.RUN With Your SOC <\/a><strong><a href=\"https:\/\/any.run\/enterprise\/?utm_source=csn&amp;utm_medium=links&amp;utm_campaign=sandbox&amp;utm_content=enterprise&amp;utm_term=0626#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Now<\/a><\/strong>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/nissan-confirms-data-breach\/\">Nissan Confirms Data Breach Following Oracle PeopleSoft 0-Day Attacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/nissan-confirms-data-breach\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Nissan Confirms Data Breach Following Oracle PeopleSoft 0-Day Attacks Nissan Americas has officially confirmed a data breach affecting current and former employees across four countries after threat actors exploited a critical zero-day vulnerability in Oracle PeopleSoft software, a campaign attributed to the ShinyHunters extortion group. The attack stems from CVE-2026-35273, a CVSS 9.8-rated unauthenticated Server-Side [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,156],"tags":[130],"class_list":["post-13962","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-data-breach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13962"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13962"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13962\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13962"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13962"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13962"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}