ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit
ID: 30dd1042-6a3f-52bf-99ef-9ac9a764942a
STIX ID: report--30dd1042-6a3f-52bf-99ef-9ac9a764942a
Feed Name: DataBreaches.Net
Mandiant and Google Threat Intelligence Group warn of an active extortion campaign by UNC6240 (ShinyHunters) exploiting a zero-day RCE (CVE-2026-35273, CVSS 9.8) in Oracle PeopleSoft Environment Management between May 27 and June 9, 2026; the attackers deployed customized MeshCentral agents and a lateral movement/defacement script, staged stolen data, and published leaks to the ShinyHunters Data Leak Site after compromising over 100 potentially vulnerable endpoints (majority in the U.S. higher education sector).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
