<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Erp-Security on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/erp-security/</link><description>Recent content in Erp-Security on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Sun, 15 Jun 2025 17:44:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/erp-security/index.xml" rel="self" type="application/rss+xml"/><item><title>ShinyHunters Breach: PeopleSoft Attacks Hit 100+ Orgs</title><link>https://zxcloudsecurity.co.uk/posts/shinyhunters-oracle-peoplesoft-breach-council-of-europe/</link><pubDate>Mon, 15 Jun 2026 17:44:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/shinyhunters-oracle-peoplesoft-breach-council-of-europe/</guid><description>ShinyHunters exploits Oracle PeopleSoft to breach the Council of Europe, Nottingham University, and 100+ other victims. What architects need to know.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/cyber-crime/2026/06/15/council-of-europe-hacked-in-shinyhunters-peoplesoft-heist/5255757">The Register — Security</a></p>
<hr>
<p>The hacking group ShinyHunters has breached the Council of Europe by exploiting vulnerabilities in Oracle PeopleSoft, the enterprise HR and administrative software used by many large organisations. The attack also affected Nottingham University and over 100 other unnamed victims, suggesting a widespread, opportunistic campaign targeting PeopleSoft deployments. The breach raises serious concerns about the exposure of sensitive personnel and organisational data held within ERP systems.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Audit all internet-facing PeopleSoft instances immediately — ensure they are patched to the latest Oracle CPU release, restrict access via IP allowlisting or VPN, and review whether PeopleSoft admin interfaces are unnecessarily exposed to the public internet. If PeopleSoft is hosted on cloud infrastructure, validate that security groups and network ACLs limit exposure appropriately.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/cyber-crime/2026/06/15/council-of-europe-hacked-in-shinyhunters-peoplesoft-heist/5255757">Council of Europe hacked in ShinyHunters&rsquo; PeopleSoft heist</a></p>
]]></content:encoded></item></channel></rss>