ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
ID: 3c298287-293b-58a4-a7e9-bed5450f826a
STIX ID: report--3c298287-293b-58a4-a7e9-bed5450f826a
Feed Name: The Hacker News
Mandiant attributes active exploitation of a critical zero-day RCE (CVE-2026-35273) in Oracle PeopleSoft to ShinyHunters/UNC6240 between May 27 and June 9; the bug required no authentication and allowed full server compromise. Attackers exfiltrated data from many organizations (notably universities), with ~455,000 unique email addresses and sensitive PII appearing in the leak; researchers discovered exposed attacker staging servers and artifacts (custom agents, lateral-movement scripts, C2 domain). Oracle released an advisory and mitigations (disable PSEMHUB or block endpoints) and Mandiant provided IOCs and hunting guidance while notifying affected organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
