#1
The Hacker News
general
June 11, 2026 at 20:29 UTC
ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
By [email protected] (The Hacker News)
AI Summary
ShinyHunters (tracked by Mandiant as UNC6240) exploited CVE-2026-35273, a critical unauthenticated RCE zero-day in Oracle PeopleSoft, between May 27 and June 9 — a full two weeks before Oracle published its advisory on June 10. Universities were the primary targets, with the University of Nottingham confirming a breach affecting over 450,000 student and alumni records. Security teams running PeopleSoft should apply Oracle's emergency patch immediately given active exploitation and the group's history of large-scale extortion campaigns.
Relevance score: 92.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →