Nissan discloses employee data breach linked to Oracle zero-day attacks
2026-06-30T07:23:30Z•dfb93be4c2095b622fc0cb3d3b21e056c376454ad63a500496d131a222e9bd60
active-exploitcisaciscocve-2026-46817cve-2026-48558data-breachdjinn-stealerexploitationkddinaicnissanoracleoracle-e-business-suitepeoplesoftphishingpolymarketshinyhunterssignalsimplehelpsupply-chainunc4221unc5792zero-day
What happened
BleepingComputer collection: multiple active exploitation and data-theft incidents. Threat actors (linked to the ShinyHunters extortion group) exploited a zero-day in Oracle PeopleSoft to steal data from organizations including Nissan and the NAIC (NAIC reports only publicly available/outdated logs and configs). Defused observed active exploitation of a critical Oracle E-Business Suite flaw. A critical SimpleHelp vulnerability (CVE-2026-48558) is being abused to deploy the cross‑platform Djinn Stealer. CISA issued an urgent patching deadline for an actively exploited Cisco Unified CM Server漏洞;
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- dfb93be4c2095b622fc0cb3d3b21e056c376454ad63a500496d131a222e9bd60
- Enrichment time
- 2026-06-30T07:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.