ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day
ID: f857628b-76e5-5104-abf2-af79d482566c
STIX ID: report--f857628b-76e5-5104-abf2-af79d482566c
Feed Name: The Register (Security)
Threat Score
ShinyHunters exploited a critical Oracle PeopleSoft zero-day (CVE-2026-35273, CVSS 9.8) to compromise more than 100 organizations—including the University of Nottingham—stealing roughly 40 GB of personal and billing records; Google telemetry and reporting corroborate active exploitation, Oracle issued mitigations, and the actor is publicly extorting victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
