Home / Jun 12, 2026 / Story
0
#1 The Hacker News general June 11, 2026 at 20:29 UTC

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

By [email protected] (The Hacker News)

AI Summary

ShinyHunters (tracked by Mandiant as UNC6240) exploited CVE-2026-35273, a critical unauthenticated RCE zero-day in Oracle PeopleSoft, between May 27 and June 9 — a full two weeks before Oracle published its advisory on June 10. Universities were the primary targets, with the University of Nottingham confirming a breach affecting over 450,000 student and alumni records. Security teams running PeopleSoft should apply Oracle's emergency patch immediately given active exploitation and the group's history of large-scale extortion campaigns.

Relevance score: 92.0/100

# More from June 12