logo

Google Confirms ShinyHunters Exploited Oracle PeopleSoft Zero-Day CVE-2026-35273

ID: e2cf38a7-6ea3-53ff-b475-559bda4cd4c2

STIX ID: report--e2cf38a7-6ea3-53ff-b475-559bda4cd4c2

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-06-14

Date Updated: 2026-06-15

...
...

Google's Threat Intelligence Group confirmed that ShinyHunters actively exploited a zero-day (CVE-2026-35273) in Oracle PeopleSoft before Oracle's public advisory, conducting rapid automated exploitation against US higher-education PeopleSoft instances, exfiltrating data and pursuing extortion; the report provides attribution evidence, remediation recommendations (immediate patching, log review, persistence checks), and forensic queries to hunt for indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.