logo

ShinyHunters Target Universities in Oracle PeopleSoft Zero-Day Attack

ID: 4f0491e5-7417-52eb-9ae4-07e1250982cf

STIX ID: report--4f0491e5-7417-52eb-9ae4-07e1250982cf

Feed Name: HackRead

Threat Score
90/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

Author: Deeba Ahmed

...
...

**Executive Summary:** A critical unauthenticated RCE zero-day (CVE-2026-35273) in Oracle PeopleSoft was actively exploited by UNC6240 (ShinyHunters) between 27 May and 9 June to compromise over 100 organizations—predominantly US universities—resulting in large-scale data theft including a reported 40 GB leak of 450,000 University of Nottingham student records; attackers used MeshCentral backdoors, credential spraying, application‑layer API abuse, and public leak sites, and Oracle has issued out‑of‑band advisories and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.