logo

ShinyHunters Uses Oracle Zero-Day to Rampage Higher Education

ID: aa3e3be8-4d5b-532d-9b5a-d69451fe585c

STIX ID: report--aa3e3be8-4d5b-532d-9b5a-d69451fe585c

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-06-13

Date Updated: 2026-06-13

...
...

ShinyHunters exploited a pre-auth zero-day (CVE-2026-35273) in Oracle PeopleSoft to breach numerous U.S. universities, stealing large volumes of student, faculty, and institutional data; Oracle issued emergency mitigations and a patch after active exploitation was reported, and the report details impacts, the actor's scale-focused playbook, and immediate remediation steps for affected institutions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.