ShinyHunters Strikes with Oracle PeopleSoft Exploit
ID: 684f7ac5-85dc-5e90-9761-9abb6072ad4f
STIX ID: report--684f7ac5-85dc-5e90-9761-9abb6072ad4f
Feed Name: securityonline.info
Mandiant and Google TAG report a global extortion campaign by ShinyHunters exploiting a critical Oracle PeopleSoft RCE (CVE-2026-35273, CVSS 9.8) as a zero-day to compromise over 100 organizations—predominantly higher education—deploy malicious MeshCentral agents, perform credential spraying and lateral movement, exfiltrate sensitive student and financial records, and publish stolen data on a leak site; the report includes attacker infrastructure details, IoCs, and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
