A single Oracle PeopleSoft bug gave ShinyHunters two weeks to ransack 100 universities before anyone noticed
A 9.8-severity zero-day in Oracle PeopleSoft gave the ShinyHunters extortion group an uncontested two-week window to breach 300-plus servers across 100 organizations, mostly universities, before Oracle issued an advisory. Moody Bible Institute alone had 2.3 million records exposed. Oracle's permanent fix arrived in its July 2026 Critical Patch Update.