Signal

ShinyHunters exploit Oracle PeopleSoft zero-day to breach over 100 organizations, mainly universities

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-06-11 20:29 UTCUpdated 2026-06-12 16:12 UTC
rss
cveexploitsbreachesmalwarethreat_actorsadvisories
Source links open
Source links and full evidence are open here. Pro adds archive history, compare-over-time, alerts, exports, and workflow. Business adds Feed API integrations and team usage.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.
4 top sources shown
Overview

A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools has been actively exploited by the ShinyHunters threat group since late May 2026. The flaw allows unauthenticated remote code execution, enabling attackers to compromise systems and steal data.

Entities
OracleGoogleMandiantShinyHuntersPeopleSoft PeopleTools
Score total
1.89
Momentum 24h
9
Evidence documents
-
Independent publishers
-
Independent origins
-
Primary sources
-
Secondary sources
-
Source types
-
Duplicate ratio
0%
Why now
  • Active exploitation detected since late May 2026, with public disclosure and patch only in June.
  • ShinyHunters publicly leaked stolen data, increasing pressure on victims and urgency for response.
  • Oracle's out-of-band patch underscores the critical severity and immediate threat posed by this flaw.
Why it matters
  • Zero-day vulnerability exploited before patch release risks widespread data breaches.
  • Higher education institutions are heavily targeted, impacting sensitive student and staff data.
  • Highlights the need for rapid vulnerability management and network segmentation for critical enterprise software.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • ShinyHunters exploited Oracle PeopleSoft zero-day CVE-2026-35273 to breach over 100 organizations, mainly universities.
  • Oracle released an out-of-band patch for CVE-2026-35273 on June 10, 2026, after active exploitation was detected.
  • The vulnerability allows unauthenticated remote code execution leading to full system compromise if PeopleSoft Environment Management Hub is internet-exposed.
How sources frame it
  • Google Threat Intelligence Group: neutral
This incident highlights the critical risk posed by zero-day vulnerabilities in widely used enterprise software and the speed at which threat actors exploit them before patches are available.
All evidence
All evidence
Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
Rapid7 · rapid7.com · 2026-06-12 13:43 UTC
Oracle fixes PeopleSoft flaw exploited by ShinyHunters
Computerweekly · computerweekly.com · 2026-06-12 12:22 UTC
Oracle PeopleSoft zero‑day fuels ShinyHunters extortion spree
Csoonline · csoonline.com · 2026-06-12 09:05 UTC
Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters
SecurityWeek · securityweek.com · 2026-06-12 06:44 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 6Origin domains: 6Duplicates: -
Showing 6 / 9
Top publishers (this list)
  • Cyberscoop (1)
  • Rapid7 (1)
  • Computerweekly (1)
  • Csoonline (1)
  • Ncsc (1)
  • SecurityWeek (1)
Top origin domains (this list)
  • cyberscoop.com (1)
  • rapid7.com (1)
  • computerweekly.com (1)
  • csoonline.com (1)
  • advisories.ncsc.nl (1)
  • securityweek.com (1)