Multiple reports describe ongoing cyberattacks in which the ShinyHunters ransomware/extortion group exploits an unpatched Oracle PeopleSoft vulnerability, CVE-2026-35273. The flaw is reported as a high-severity issue that can be exploited remotely over the internet without authentication, enabling attackers to gain access to enterprise systems and steal data. Several outlets report that activity spanned late May through early June, with targets including American higher-education organizations. Google’s Mandiant links the activity to a threat actor it tracks as UNC6240 and reports dates for the campaign. Bleeping Computer reports that the vulnerability is actively exploited in ShinyHunters-related data theft attacks, while SecurityWeek reports that Oracle has issued mitigation/patch information but had not initially publicly confirmed whether the vulnerability was being exploited as a zero-day at the time of its advisory. SecurityWeek also reports that Google confirms exploitation, even though Oracle’s public confirmation lags. The Next Web and TechRadar report that more than 100 organizations were impacted. Oracle later releases additional guidance/mitigation, but the coverage notes uncertainty in the timeline of patch availability versus exploitation.
ShinyHunters exploits Oracle PeopleSoft zero-day to breach universities and other organizations
Multiple reports describe ongoing cyberattacks in which the ShinyHunters ransomware/extortion group exploits an unpatched Oracle PeopleSoft vulnerability, CVE-2026-35273. The flaw is reported as a hig...
- Attackers associated with ShinyHunters exploit Oracle PeopleSoft vulnerability CVE-2026-35273.
- CVE-2026-35273 is described as remotely exploitable over the internet without authentication (CVSS reported as very high, 9.8).
- Google’s Mandiant attributes the activity to the UNC6240 threat actor and places activity roughly between May 27 and June 9.
- Reports indicate the vulnerability is exploited in data theft/extortion campaigns, affecting more than 100 organizations, including universities.
- Oracle releases or updates mitigation/patch information, while initial public confirmation about in-the-wild zero-day exploitation varies by outlet’s reporting.
A major bug in Oracle's ERP software disproportionately affected American universities, and hackers have capitalized by stealing gobs of data.
2 months agoHigh-severity CVSS 9.8 PeopleSoft vulnerability caused over 100 organizations to become victims, including universities.
2 months agoOracle has mitigated CVE-2026-35273, but it has not publicly confirmed the vulnerability’s in-the-wild exploitation. The post Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters appeared first on SecurityWeek.
2 months agoOracle warned customers on Thursday of a critical vulnerability in its PeopleSoft software that hackers have already exploited to breach more than 100 organisations. The flaw, CVE-2026-35273, carries a CVSS score of 9.8 and can be exploited over the internet without any authentication. Oracle has not released a patch. The advisory came a day after […] This story continues at The Next Web
2 months agoThe ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest. Google's Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9. Oracle did not publish its advisory until June 10, so the bug was a
2 months agoOracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks. [...]
2 months ago
UK warns against expelling British officials from Gaza ceasefire coordination center
The UK government warns that Israel should not remove British officials from a Gaza ceasefire coordination center. The w...
Russian drone attacks hit Kyiv region, damaging apartments and warehouses for a second day
Russian forces carry out a second day of drone attacks on Ukraine’s Kyiv region, striking multiple buildings including a...
Dutch court convicts and sentences Rwandan man to life for 1994 genocide role
A Dutch court convicts a Rwandan man of participating in and inciting the 1994 genocide in Rwanda and sentences him to l...