ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to… | HappeningNow.news

Cybersecurity · 39 views

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest.

Source AI Summary Published June 11, 2026 Brief Under 1 min brief
Story intelligence
Coverage Single outlet Single-outlet story
Views 39 Community interest
Brief read Under 1 min brief 106 words

AI Summary

A cybersecurity incident involved the exploitation of a zero-day vulnerability in Oracle PeopleSoft, resulting in data breaches at universities. The vulnerability, identified as CVE-2026-35273, was used by the ShinyHunters extortion crew to gain unauthorized access to enterprise systems. The campaign, which occurred between May 27 and June 9, targeted universities and led to the theft of data, with the attackers demanding payment in exchange for keeping the stolen information private. The incident was attributed to the UNC6240 group by Google's Mandiant. The Oracle advisory for the vulnerability was not published until June 10, after the exploitation had already occurred, indicating a delay in disclosing the issue.

AI summaries can be wrong sometimes—always verify important details using the source article.

How AI & Automation are used
Read original at The Hackernews

Coverage Context

Part of Peoplesoft coverage 12 tracked stories
Explore Peoplesoft

More from Cybersecurity

Continue reading recent Cybersecurity coverage

Support HappeningNow

Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.

Support HappeningNow

Report an issue with this page