ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed
ID: 62df9772-8153-5528-94a4-2ae0ad6f1701
STIX ID: report--62df9772-8153-5528-94a4-2ae0ad6f1701
Feed Name: Dark Reading
ShinyHunters exploited a critical zero-day (CVE-2026-35273, CVSS 9.8) in Oracle PeopleSoft's PeopleTools EMHub to perform unauthenticated remote code execution between May 27 and June 9, 2026, compromising over 300 PeopleSoft instances across more than 100 organizations (predominantly higher education), exfiltrating sensitive data (including student records), and publishing stolen data; researchers observed use of MeshCentral for C2, credential spraying, and Zstandard for mass exfiltration, and Oracle released a patch and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
