U.S. CISA adds Oracle PeopleSoft Enterprise PeopleTools flaw to its Known Exploited Vulnerabilities catalog
ID: aa35b561-220a-5535-be17-481b04eb810e
STIX ID: report--aa35b561-220a-5535-be17-481b04eb810e
Feed Name: Security Affairs
The report describes an active zero-day exploitation campaign (May 27–June 9, 2026) against Oracle PeopleSoft PeopleTools (CVE-2026-35273, CVSS 9.8) attributed to ShinyHunters/UNC6240: attackers used MeshCentral agents and acme-client-issued TLS certificates for C2, performed lateral movement and credential spraying, left extortion markers, and exfiltrated sensitive data (including ~455k email records); CISA added the CVE to its KEV catalog and ordered federal mitigation by June 15, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
