logo

ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed

ID: 62df9772-8153-5528-94a4-2ae0ad6f1701

STIX ID: report--62df9772-8153-5528-94a4-2ae0ad6f1701

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-06-12

Date Updated: 2026-06-15

Author: Nate Nelson

...
...

ShinyHunters exploited a critical zero-day (CVE-2026-35273, CVSS 9.8) in Oracle PeopleSoft's PeopleTools EMHub to perform unauthenticated remote code execution between May 27 and June 9, 2026, compromising over 300 PeopleSoft instances across more than 100 organizations (predominantly higher education), exfiltrating sensitive data (including student records), and publishing stolen data; researchers observed use of MeshCentral for C2, credential spraying, and Zstandard for mass exfiltration, and Oracle released a patch and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.