logo

Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters

ID: 4047ace9-9efc-51fc-80ff-3ed53472b4e3

STIX ID: report--4047ace9-9efc-51fc-80ff-3ed53472b4e3

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

Author: Guru Baran

...
...

**Oracle PeopleSoft zero-day exploited in active extortion campaign:** Mandiant and Google TAG warn that UNC6240 (ShinyHunters) actively exploited a critical unauthenticated RCE (CVE-2026-35273, CVSS 9.8) in Oracle PeopleSoft (PSEMHUB) between May 27 and June 9, 2026, using staged servers (142.11.200.186–190), masqueraded MeshCentral agents (e.g., meshagent64-azure-ops.exe) and the domain azurenetfiles.net for C2; attackers performed reconnaissance, lateral movement, compressed exfiltration archives and posted stolen data to a public data leak site, impacting primarily higher education organizations and resulting in confirmed data loss (≈40 GB) for at least one university.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.