Google Confirms ShinyHunters Exploited Oracle PeopleSoft Zero-Day CVE-2026-35273
ID: e2cf38a7-6ea3-53ff-b475-559bda4cd4c2
STIX ID: report--e2cf38a7-6ea3-53ff-b475-559bda4cd4c2
Feed Name: CosmicBytez Labs
Threat Score
Google's Threat Intelligence Group confirmed that ShinyHunters actively exploited a zero-day (CVE-2026-35273) in Oracle PeopleSoft before Oracle's public advisory, conducting rapid automated exploitation against US higher-education PeopleSoft instances, exfiltrating data and pursuing extortion; the report provides attribution evidence, remediation recommendations (immediate patching, log review, persistence checks), and forensic queries to hunt for indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
