logo

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

ID: 30dd1042-6a3f-52bf-99ef-9ac9a764942a

STIX ID: report--30dd1042-6a3f-52bf-99ef-9ac9a764942a

Feed Name: DataBreaches.Net

Threat Score
88/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

Author: Dissent

...
...

Mandiant and Google Threat Intelligence Group warn of an active extortion campaign by UNC6240 (ShinyHunters) exploiting a zero-day RCE (CVE-2026-35273, CVSS 9.8) in Oracle PeopleSoft Environment Management between May 27 and June 9, 2026; the attackers deployed customized MeshCentral agents and a lateral movement/defacement script, staged stolen data, and published leaks to the ShinyHunters Data Leak Site after compromising over 100 potentially vulnerable endpoints (majority in the U.S. higher education sector).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.