Signal
ShinyHunters exploits Oracle PeopleSoft zero-day to breach over 100 organizations including universities and Council of Europe
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-06-15 17:44 UTCUpdated 2026-06-15 21:21 UTC
rss
cveexploitsbreachesthreat_actorsincident_response
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.2 top sources shown
limited source diversity in top sources
Overview
The ShinyHunters cybercrime group has exploited a critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft to compromise more than 100 organizations worldwide. The majority of confirmed victims are higher education institutions, including the University of Nottingham, as well as the Council of Europe.
Entities
OracleMandiantGooglePeopleSoft
Score total
0.85
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
- The zero-day vulnerability (CVE-2026-35273) remains unpatched, enabling ongoing exploitation by ShinyHunters.
- Recent data leaks and extortion attempts have increased pressure on affected organizations to respond quickly.
- Public disclosure by researchers and media raises awareness of the widespread impact across sectors globally.
Why it matters
- Highlights critical risk of zero-day vulnerabilities in widely used enterprise software like Oracle PeopleSoft.
- Demonstrates targeted attacks on higher education and international organizations with sensitive personal data at risk.
- Underlines the urgency for organizations to patch vulnerabilities and improve incident response to active extortion threats.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
- ShinyHunters exploited a critical zero-day vulnerability in Oracle PeopleSoft to breach over 100 organizations globally, mostly universities.
- The Council of Europe was hacked by ShinyHunters, resulting in theft of over 297 GB of sensitive HR and payroll data.
How sources frame it
- Mandiant And Google's Threat Intelligence Group: neutral
- The Register Security: neutral
This ongoing storyline highlights the widespread impact of a critical Oracle PeopleSoft zero-day exploited by ShinyHunters, emphasizing the need for urgent patching and incident response.
All evidence
All evidence
ShinyHunters Hits Universities Via Oracle Zero-Day
BankInfoSecurity · bankinfosecurity.com · 2026-06-15 21:21 UTC
Council of Europe hacked in ShinyHunters' PeopleSoft heist
The Register Security · theregister.com · 2026-06-15 17:44 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
- BankInfoSecurity (1)
- The Register Security (1)
Top origin domains (this list)
- bankinfosecurity.com (1)
- theregister.com (1)