Logo
News Ababil
Explore
SYS_NODE: ONLINE // Cyber Security

ShinyHunters Weaponizes Oracle PeopleSoft zero‑day (CVE‑2026‑35273) to Assault Universities

DECRYPTED BY: Kaelen Frost | TIMESTAMP: 2026-06-12 T 09:19:31 Z | [ 1 MIN READ ]
ShinyHunters Weaponizes Oracle PeopleSoft zero‑day (CVE‑2026‑35273) to Assault Universities
1 Min Read
Share

The ShinyHunters extortion gang leveraged the Oracle PeopleSoft zero‑day (CVE‑2026‑35273) to infiltrate multiple university networks, pilfering sensitive records and threatening exposure unless a ransom was paid.

Oracle PeopleSoft zero‑day fuels campus breaches

Activity, traced by Mandiant, spanned ↓ 14 days from May 27 to June 9, with Oracle’s advisory appearing only on June 10, a ↓ 1 day lag that left institutions exposed. University IT teams scrambled to patch systems while attackers exfiltrated data. Google’s Mandiant attributes the operation to the UNC6240 group, known for ransomware‑as‑a‑service campaigns.

“The rapid exploitation of an unpatched PeopleSoft flaw underscores the need for continuous vulnerability management,” a security analyst told Reuters.

The breach highlights how legacy ERP platforms remain attractive targets, prompting calls for tighter supply‑chain oversight. For further context, see the analysis by Bloomberg.

Analysis by: Kaelen Frost
Lead Cybersecurity Analyst
Global Data Feed

More from this Intel

Microsoft patches 570 security flaws in record‑breaking July update

Microsoft patches 570 security flaws in record‑breaking July update

Jul 21, 2026
AI safety guardrails blocked defenders, not attackers, in Hugging Face breach

AI safety guardrails blocked defenders, not attackers, in Hugging Face...

Jul 20, 2026
HollowGraph Malware Hijacks Microsoft 365 Calendar to Funnel Data to 2050

HollowGraph Malware Hijacks Microsoft 365 Calendar to Funnel Data to...

Jul 20, 2026
Zero‑Day WordPress Core Flaw Exposes Sites to Unauthenticated Code Execution

Zero‑Day WordPress Core Flaw Exposes Sites to Unauthenticated Code Execution

Jul 19, 2026
Capital One Unveils VulnHunter: Open‑Source AI Tool to Preempt Software Exploits

Capital One Unveils VulnHunter: Open‑Source AI Tool to Preempt Software...

Jul 18, 2026
Brex Reinvents AI Agent Policy with Network‑Level Enforcement, Not Pre‑Written Rules

Brex Reinvents AI Agent Policy with Network‑Level Enforcement, Not Pre‑Written...

Jul 18, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.