ShinyHunters Target Universities in Oracle PeopleSoft Zero-Day Attack
ID: 4f0491e5-7417-52eb-9ae4-07e1250982cf
STIX ID: report--4f0491e5-7417-52eb-9ae4-07e1250982cf
Feed Name: HackRead
**Executive Summary:** A critical unauthenticated RCE zero-day (CVE-2026-35273) in Oracle PeopleSoft was actively exploited by UNC6240 (ShinyHunters) between 27 May and 9 June to compromise over 100 organizations—predominantly US universities—resulting in large-scale data theft including a reported 40 GB leak of 450,000 University of Nottingham student records; attackers used MeshCentral backdoors, credential spraying, application‑layer API abuse, and public leak sites, and Oracle has issued out‑of‑band advisories and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
