Multiple reports describe ongoing cyberattacks in which the ShinyHunters ransomware/extortion group exploits an unpatched Oracle PeopleSoft vulnerability, CVE-2026-35273. The flaw is reported as a high-severity issue that can be exploited remotely over the internet without authentication, enabling attackers to gain access to enterprise systems and steal data. Several outlets report that activity spanned late May through early June, with targets including American higher-education organizations. Google’s Mandiant links the activity to a threat actor it tracks as UNC6240 and reports dates for the campaign. Bleeping Computer reports that the vulnerability is actively exploited in ShinyHunters-related data theft attacks, while SecurityWeek reports that Oracle has issued mitigation/patch information but had not initially publicly confirmed whether the vulnerability was being exploited as a zero-day at the time of its advisory. SecurityWeek also reports that Google confirms exploitation, even though Oracle’s public confirmation lags. The Next Web and TechRadar report that more than 100 organizations were impacted. Oracle later releases additional guidance/mitigation, but the coverage notes uncertainty in the timeline of patch availability versus exploitation.