Nissan employee data exposed in Oracle zero-day breach
Automaker warns current and former staff after attackers exploited PeopleSoft flaw previously linked to ShinyHunters extortion group.
Nissan has disclosed a data breach affecting employee records after threat actors exploited a vulnerability in Oracle's PeopleSoft platform. The company is notifying current and former employees whose personal information was accessed during the incident.
The breach stems from exploitation of an Oracle PeopleSoft zero-day vulnerability that has been linked to attacks attributed to the ShinyHunters extortion group. ShinyHunters has previously claimed responsibility for high-profile data thefts targeting major corporations and cloud service providers. The group typically exfiltrates data and threatens public release unless ransom demands are met.
Oracle PeopleSoft is widely deployed across enterprise human resources and financial management systems, making it a high-value target for threat actors seeking employee records, payroll data, and corporate financial information. The vulnerability's zero-day status indicates it was exploited before Oracle released a patch, leaving organizations exposed during the window between discovery and remediation.
- 01Nissan employees face elevated identity theft and phishing risk from exposed personal data.
- 02Organizations using Oracle PeopleSoft must audit systems for compromise and apply emergency patches.
- 03ShinyHunters' targeting of enterprise HR systems signals continued focus on high-value employee databases.
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.