Signal

Oracle PeopleSoft zero-day exploited by ShinyHunters in university-targeted extortion campaign

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-06-12 06:44 UTCUpdated 2026-06-12 16:12 UTC
rss
cveexploitsbreachesthreat_actorssecurity_advisoryincident_response
Source links open
Source links and full evidence are open here. Pro adds archive history, compare-over-time, alerts, exports, and workflow. Business adds Feed API integrations and team usage.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.
4 top sources shown
Overview

A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 has been actively exploited by the ShinyHunters cybercriminal group since at least May 27, 2026.

Entities
OracleGoogleMandiantUniversity of NottinghamPeopleSoft Enterprise PeopleTools
Score total
1.66
Momentum 24h
6
Evidence documents
-
Independent publishers
-
Independent origins
-
Primary sources
-
Secondary sources
-
Source types
-
Duplicate ratio
0%
Why now
  • Active exploitation began weeks before Oracle's public advisory and patch release.
  • Over 100 organizations, mostly universities, were potentially exposed and targeted.
  • Stolen data has already been leaked publicly, increasing urgency for affected entities to respond.
Why it matters
  • Highlights the risk of unpatched critical vulnerabilities in widely used enterprise software.
  • Demonstrates the threat posed by financially motivated cybercriminal groups targeting education sector.
  • Underlines the importance of rapid vulnerability disclosure and patching to prevent data breaches and extortion.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft to conduct extortion campaigns targeting universities.
  • Oracle released an out-of-band patch and advisory for CVE-2026-35273 on June 10, 2026, after active exploitation was detected.
  • Google Threat Intelligence Group confirmed exploitation of the Oracle PeopleSoft zero-day and notified over 100 potentially affected organizations, mostly in higher education.
How sources frame it
  • CSO Online: neutral
  • Rapid7: neutral
  • SecurityWeek: neutral
All evidence
All evidence
Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
Rapid7 · rapid7.com · 2026-06-12 13:43 UTC
Oracle fixes PeopleSoft flaw exploited by ShinyHunters
Computerweekly · computerweekly.com · 2026-06-12 12:22 UTC
Oracle PeopleSoft zero‑day fuels ShinyHunters extortion spree
Csoonline · csoonline.com · 2026-06-12 09:05 UTC
Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters
SecurityWeek · securityweek.com · 2026-06-12 06:44 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 6Origin domains: 6Duplicates: -
Showing 6 / 6
Top publishers (this list)
  • Cyberscoop (1)
  • Rapid7 (1)
  • Computerweekly (1)
  • Csoonline (1)
  • Ncsc (1)
  • SecurityWeek (1)
Top origin domains (this list)
  • cyberscoop.com (1)
  • rapid7.com (1)
  • computerweekly.com (1)
  • csoonline.com (1)
  • advisories.ncsc.nl (1)
  • securityweek.com (1)