logo

Oracle PeopleSoft RCE Flaw Used as Zero-Day in Ongoing ShinyHunters Campaign

ID: a3442123-7bcd-571c-a3e8-176f3ce097fa

STIX ID: report--a3442123-7bcd-571c-a3e8-176f3ce097fa

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

Author: Pierluigi Paganini

...
...

ShinyHunters exploited a critical Oracle PeopleSoft zero-day (CVE-2026-35273, CVSS 9.8) between May 27 and June 9 to compromise over 100 organizations—mostly universities—deploy MeshCentral-based agents for persistence and lateral movement, exfiltrate sensitive PII (approximately 455,000 email/identity records) to a public leak mirror, and perform extortion; the report details IOCs, attack scripts, C2 infrastructure and recommends isolating or blocking PSEMHUB/PSIGW endpoints and hunting for indicators in WebLogic logs and outbound connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.