A message landed in my inbox on Tuesday, while I was on vacation, that I have not stopped thinking about.
It was four words long.
“We were number 47.”
Ray runs PeopleTools for a mid-size university system. I have known him for a few years. He is the kind of admin who can tell you which projects reference PSEMHUB without opening App Designer.
He’s Quiet and yet he is Careful. He’s the person you want holding the keys when things go sideways.
Number 47 meant his environment was one of the ones the Not-So ShinyHunters walked into between May 27 and June 9. His instance ran PeopleTools 8.61, and the Environment Management Hub was reachable from outside the network. That is the door. The Not-So ShinyHunters chain ran CVE-2026-35278 into CVE-2026-35273, pre-authentication remote code execution through PSEMHUB, CVSS 9.8.
Oracle finally closed it in the latest July Critical Patch Update that came in last week. And that was part of a record release of more than 1,400 fixes from Oracle.
Ray spent the next week doing the unglamorous work. Rotating credentials. Reading access logs line by line. Rebuilding trust in an environment that no longer felt like his.
More than 100 organizations got the same call, roughly two-thirds of them universities and colleges. His was one of three hundred servers.
Then something happened that had nothing to do with his breach.
His phone started buzzing.
Three recruiters, in the same week he was heads-down firefighting, reached out. None of them knew his campus had been hit. They were not calling about his incident. They were calling because every organization running PeopleSoft read the same headline he did, felt the same cold drop in their stomach, and asked the same question at once.
Who here actually understands PeopleTools security?
And in that moment, the market went looking. Even the Workday and Oracle Cloud recruiters were saying…
I thought we were done with PeopleSoft Recruiting! Crap! I should have kept my list of PeopleSoft resumes and experts.
Nonetheless, The market scanned LinkedIn, old PeopleSoft contact lists, community forums. They even registered in the PeopleSoft Community looking..
It reached for anyone who looked like they knew PeopleSoft and PeopleTools PSEMHUB from PSADMIN.
Anyways, I digress. Then, Ray came up. Not because he was the best security admin in the country. Because he was already visible at the exact moment the market panicked.
But this isn’t really about an Oracle / PeopleSoft patch.
Ray didn’t get found because of the breach. He got found because the breach made the market look, and when it looked, he was already standing where the light was, shining with all the right signals, keywords, and readiness.
It is the short, unpredictable stretch when a crisis forces an entire market to hunt for a specific skill, and the only people who get pulled through are the ones already visible before the window opened.
Here is the part that stings. The window closes fast. In two or three months, the panic hiring settles, the urgent contracts get filled, and the market stops looking as hard. The PeopleSoft admins who were invisible during those weeks did not lose because they lacked the skill. Plenty of them could have rebuilt Ray’s environment in their sleep. They lost because when the market reached out its hand, it could not find them.
I almost missed all of this myself while on vacation last week. I saw the July CPU headline on my phone, thought “another Oracle patch,” and nearly scrolled past. Treat the news as weather, something that happens to other people, and get back to the ticket queue.
“I keep my head down and do the work. The right people already know what I can do.”
I hear this constantly, and I understand it. Twenty years in, your work should speak for itself. But the market does not hear whispers between the people who already know you. During an exposure window, the campus or org scrambling to patch its PeopleTools estate is not calling your old manager for a reference. It is typing “PeopleSoft security consultant” into a search bar and hiring whoever the results surface first. Your reputation is real. It is also trapped inside a room the market cannot see into.
The fix is not louder self-promotion. It is leaving a trail. Ray had answered a handful of PeopleTools security questions in a community thread months earlier, back when none of it felt urgent. That trail is what the recruiters found. He was visible before he needed to be, which is the only kind of visibility that pays.
If you are a manager or director and own the budget or the roadmap, the exposure window is a retention story you are probably misreading. The person who can calmly triage a PSEMHUB exposure at 2 a.m. is the same person three recruiters are calling this month. Your risk is not only the unpatched server. It is that the one admin who understands it is now, for the first time, extremely easy for someone else to find.
If your PeopleSoft role was eliminated tomorrow, and the market went looking for someone exactly like you next week, how long would it take before it found you?
Reply and tell me or leave a comment. I read every response.
Lost under the breach noise: Oracle extended Premier Support through at least 2037, with annual extensions now the stated practice.
The PeopleTools 8.63 roadmap is not a maintenance release. It adds a Model Context Protocol server for secured access to PeopleSoft data, LLM-assisted code tools in Application Designer, natural language and semantic search, plus SAML single sign-on and TOTP multifactor authentication.
Read that security line again in light of this week. Oracle is handing you SAML and TOTP at the same moment attackers are proving what an exposed 8.61 environment costs.
Somewhere in Tennessee this month, a Nissan payroll employee opened a letter that began “We are writing to inform you.” Nissan Americas runs payroll, tax administration, and personnel records on PeopleSoft, and in July it disclosed that employee data was taken in this same breach wave, tied to CVE-2026-35273. NAIC was hit too, with data linked to Moody’s, Fitch, Kroll, and AM Best.
For six weeks, every team on PeopleTools 8.61 or 8.62 lived on mitigations: isolate the endpoint, watch the logs, hope. The July CPU is the first permanent fix for the chain ShinyHunters used, CVE-2026-35278 into CVE-2026-35273 for remote code execution through PSEMHUB. Eighty-four of the CPU’s fixes were PeopleSoft-specific. Sixty-eight percent of the June victims were higher ed.
The orgs breached in June were unlucky. The orgs breached in September will have skipped a fix that sat available for two months. So this is the week your CPU cycle earns its keep:
Get the July CPU into a test environment now, not at quarter end
Keep /PSEMHUB/* isolated from external access until the patch is verified in production
Pull the accounts holding the PeopleSoft Administrator role and cut the list down while you have leadership’s attention
If you are in higher ed, assume you are on the target list
The average PeopleSoft salary sits at $141,741, with top earners past $175,500. Security skills carry a 15 to 25 percent premium, cloud skills 25 to 40 percent, and roughly 30 percent of postings are remote. Those premiums are not rewards for certificates. They are what the market pays to find scarce, visible expertise fast, and this week it needed to find it faster than usual.
Security and PeopleTools admin roles are the most urgent hires right now, and the breach is why. When an environment gets compromised, organizations do not post “Nice to Have” reqs. They post “Start Monday.”
Recent roles from the last seven days on the board:
ERP Systems Analyst (PeopleSoft HCM / FMS / CS) - Galveston, TX (Remote/Texas) - UTMB Health - Contract
Sr. Programmer Analyst, PeopleSoft - Remote (Orlando, FL) - Darden Restaurants - Full-time
Director of Enterprise Applications, PeopleSoft / HCM - Boston, MA - City of Boston - Full-time
PeopleSoft Business Analyst (Data Migration) - New York, NY - Trigyn - Onsite
Power Platform / PeopleSoft-adjacent Developer - St. Paul, MN - Trigyn - Contract
Software Developer (Dynamics 365 / Oracle) - Albany, NY - Trigyn - Full-time
Operations Coordinator, Systems - Chicago, IL - Northwestern Memorial Hospital - Full-time
ServiceNow / Integration Developer - St. Paul, MN - Trigyn - Contract
View all open PeopleSoft roles:
PeopleTools 8.63: Inside Oracle’s 2026 PeopleSoft Update - MCP servers, semantic search, and TOTP, decoded for the people who have to build it, not just read about it. https://blog.peoplesoftcareer.com/peopletools-8-63-2026-update/
PeopleSoft AI Enablement: What PeopleTools 8.63 Delivers - The Natural Language Assistant and Code Assist, and what they change in your day. https://blog.peoplesoftcareer.com/peoplesoft-ai-enablement/
See you next week.
Derek Tomei
Founder, PeopleSoftCareer
The breach opened a window. The market looked through it. It only found the people who were already standing there.
P.S. If this hit home, the free 40 AI Prompts guide includes the exact ones I use to turn quiet expertise into a visible trail, the kind recruiters find before you need them to. ai.peoplesoftcareer.com

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.