logo

ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day

ID: f857628b-76e5-5104-abf2-af79d482566c

STIX ID: report--f857628b-76e5-5104-abf2-af79d482566c

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2026-06-11

Date Updated: 2026-06-12

...
...

ShinyHunters exploited a critical Oracle PeopleSoft zero-day (CVE-2026-35273, CVSS 9.8) to compromise more than 100 organizations—including the University of Nottingham—stealing roughly 40 GB of personal and billing records; Google telemetry and reporting corroborate active exploitation, Oracle issued mitigations, and the actor is publicly extorting victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.