logo

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

ID: 3c298287-293b-58a4-a7e9-bed5450f826a

STIX ID: report--3c298287-293b-58a4-a7e9-bed5450f826a

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-06-11

Date Updated: 2026-06-12

Author: [email protected] (The Hacker News)

...
...

Mandiant attributes active exploitation of a critical zero-day RCE (CVE-2026-35273) in Oracle PeopleSoft to ShinyHunters/UNC6240 between May 27 and June 9; the bug required no authentication and allowed full server compromise. Attackers exfiltrated data from many organizations (notably universities), with ~455,000 unique email addresses and sensitive PII appearing in the leak; researchers discovered exposed attacker staging servers and artifacts (custom agents, lateral-movement scripts, C2 domain). Oracle released an advisory and mitigations (disable PSEMHUB or block endpoints) and Mandiant provided IOCs and hunting guidance while notifying affected organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.