Cybersecurity · 39 views
ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest.
AI Summary
A cybersecurity incident involved the exploitation of a zero-day vulnerability in Oracle PeopleSoft, resulting in data breaches at universities. The vulnerability, identified as CVE-2026-35273, was used by the ShinyHunters extortion crew to gain unauthorized access to enterprise systems. The campaign, which occurred between May 27 and June 9, targeted universities and led to the theft of data, with the attackers demanding payment in exchange for keeping the stolen information private. The incident was attributed to the UNC6240 group by Google's Mandiant. The Oracle advisory for the vulnerability was not published until June 10, after the exploitation had already occurred, indicating a delay in disclosing the issue.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedCoverage Context
More from Cybersecurity
Continue reading recent Cybersecurity coverage
- 220 million traveler records exposed in Vietnam-linked APIS leakContinue reading
- Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data SharingContinue reading
- PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command ExecutionContinue reading
- Magento StyleSmuggler zero-day exploited to deploy Linux backdoorContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow