CVE Tools

Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack

SecurityWeekBy Eduard Kovacs

Reported exploitedOracle PeopleSoftShinyHunters

Our summary

The National Association of Insurance Commissioners (NAIC) says it was targeted in the recent Oracle PeopleSoft attack chain involving the zero-day vulnerability CVE-2026-35273, which enables unauthenticated remote code execution. NAIC reports unauthorized access discovered on June 11, with attackers obtaining statutory financial reporting and related technical data; however, it states personally identifiable information and payment/financial account details were not compromised. The incident matters because a widely used enterprise platform vulnerability is being actively leveraged by the ShinyHunters group and regulators are now confirming real-world impact.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store