INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ShinyHunters Exploits Oracle Zero-Day in Higher Ed Rampage
| 2026-06-12 14:06 CRITICAL HIGHExecutive Summary AI-generated
The ShinyHunters extortion gang has exploited a zero-day vulnerability in Oracle's PeopleSoft software suite to steal data from potentially more than 100 organizations. This attack, which began on May 27 and ended on June 9, targeted the Education Sector, with several higher education institutions falling victim. The group used a custom SSH credential spraying script to spread further into victims' environments, followed by a reconnaissance phase using MeshCentral's command line interface CLI to gather information. They then exfiltrated data using the Zstandard compression algorithm and performed remote code execution without authentication required. This exploit has been assigned a label CVE-2026-35273 with a critical 9.8 CVSS score, making it a high-risk threat for organizations relying on Oracle's PeopleSoft software suite.
Technical Mitigations AI-generated
* Regularly update and patch Oracle's PeopleSoft software suite: Ensure that all versions of the application are up-to-date with the latest security patches, as these fixes often include exploits for previously discovered vulnerabilities.
* Implement a robust incident response plan: Establish a clear process for responding to incidents like this one, including procedures for identifying, containing, and mitigating attacks. This will help minimize damage and prevent further exploitation of the same vulnerability.
* Use secure authentication mechanisms: Ensure that all systems and applications use strong authentication protocols, such as multi-factor authentication (MFA), to prevent unauthorized access even if an attacker gains remote code execution through a zero-day exploit like this one.
* Monitor for suspicious activity and implement network segmentation: Regularly monitor system logs and network traffic for signs of unusual activity. Implement network segmentation to limit the spread of malware and data exfiltration, making it more difficult for attackers to move laterally within an organization's network.
* Educate users about phishing and social engineering tactics: Remind employees that they should be cautious when clicking on links or providing sensitive information online, as these can be used by attackers to gain access to systems. Encourage them to verify the authenticity of emails and messages before responding.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign
ShinyHuntersCampaign
ShinyHunters
CVE-2026-35273CVE-2026-35273
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
educationeducation
governmentgovernment
technologytechnology
Incident Timeline
May 27, 2026
ShinyHunters exploited a previously unknown Oracle zero-day in higher education attacks.
May 27
ShinyHunters exploited CVE-2026-35273 in Oracle PeopleSoft PeopleTools version 1.1.59 to target higher education organizations on May 27.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-35273
The attacks date back to at least May 27, according to Mandiant, and involve the exploitation of
CVE-2026-35273
, a defect in Oracle PeopleSoft PeopleTools that allows unauthenticated attackers to execute remote code and takeover affected servers.
ShinyHunters Tags Universities
Beginning on May 27, ShinyHunters exploited CVE-2026-35273 across global organizations, according to Mandiant and GTIG.
organisation
Oracle PeopleSoft PeopleTools
The attacks date back to at least May 27, according to Mandiant, and involve the exploitation of
CVE-2026-35273
, a defect in Oracle PeopleSoft PeopleTools that allows unauthenticated attackers to execute remote code and takeover affected servers.
organisation
Mandiant
The attacks date back to at least May 27, according to Mandiant, and involve the exploitation of
CVE-2026-35273
, a defect in Oracle PeopleSoft PeopleTools that allows unauthenticated attackers to execute remote code and takeover affected servers.
organisation
CVE-2026
ShinyHunters Tags Universities
Beginning on May 27, ShinyHunters exploited CVE-2026-35273 across global organizations, according to Mandiant and GTIG.
infrastructure
1.1.59
On May 27 at 22:14 UTC, the attackers installed MeshCentral version 1.1.59.
organisation
UTC
On May 27 at 22:14 UTC, the attackers installed MeshCentral version 1.1.59.
between May 27, 2026
ShinyHunters exploited CVE-2026-35273 in the Environment Management component of a higher education institution between May 27, 2026.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-35273
The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of
CVE-2026-35273
, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component.”
vulnerability
CVSS 9.8
The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of
CVE-2026-35273
, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component.”
tactic
Remote Code Execution
The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of
CVE-2026-35273
, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component.”
June 9, 2026
ShinyHunters exploited CVE-2026-35273 in a higher education attack using Remote Code Execution.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-35273
The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of
CVE-2026-35273
, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component.”
vulnerability
CVSS 9.8
The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of
CVE-2026-35273
, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component.”
tactic
Remote Code Execution
The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of
CVE-2026-35273
, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component.”
June 9
Threat actors exploited an Oracle Zero-Day in the Higher Ed sector to gain unauthorized access.
June 10, 2026
ShinyHunters exploited an Oracle Zero-Day in the targeted Higher Ed entity's systems.
Click on any entity below to view its context and source!
organisation
Oracle’s
Because this activity predates Oracle’s June 10, 2026 advisory, the vulnerability was exploited as a zero-day.”
10 June 2026
Threat actors exploited an Oracle Zero-Day vulnerability in the company's database.
June 10
Threat actors exploited an Oracle Zero-Day vulnerability in the company's database, targeting higher education institutions on June 10.
Jun 11, 2026
ShinyHunters exploited a previously unknown Oracle zero-day in higher education attacks.
June 11
Mandiant and Google's Threat Intelligence Group analyzed an active ShinyHunters campaign on June 11.
Click on any entity below to view its context and source!
attribution
Mandiant
Mandiant and Google’s Threat Intelligence Group published an analysis of an active
ShinyHunters
campaign on June 11, one day after Oracle finally issued an advisory for the vulnerability being exploited.
attribution
Google’s Threat Intelligence Group
Mandiant and Google’s Threat Intelligence Group published an analysis of an active
ShinyHunters
campaign on June 11, one day after Oracle finally issued an advisory for the vulnerability being exploited.
between 27 May and 9 June
ShinyHunters exploited a critical Oracle zero-day flaw (CVE-2026-35273, CVSS 9.8) in higher education networks between May 27 and June 9.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-35273
Reportedly, the activity occurred between 27 May and 9 June, and involved the exploitation of a critical
zero-day
flaw (tracked as
CVE-2026-35273
CVSS 9.8) to compromise university networks.
vulnerability
CVSS 9.8
Reportedly, the activity occurred between 27 May and 9 June, and involved the exploitation of a critical
zero-day
flaw (tracked as
CVE-2026-35273
CVSS 9.8) to compromise university networks.
2026/06/12
ShinyHunters exploited an Oracle Zero-Day in the PeopleSoft ERP system to launch attacks on higher education institutions.
Click on any entity below to view its context and source!
organisation
ERP
Expert perspective:
“The Oracle PeopleSoft breach is an example of the new kind of attacks every ERP will face in today’s new agentic world.
industry
Technology
We have observed ShinyHunters sending extortions as recently as today,” Charles Carmakal, chief technology officer at Mandiant Consulting, told CyberScoop Thursday evening.
organisation
Mandiant Consulting
We have observed ShinyHunters sending extortions as recently as today,” Charles Carmakal, chief technology officer at Mandiant Consulting, told CyberScoop Thursday evening.
organisation
CyberScoop
We have observed ShinyHunters sending extortions as recently as today,” Charles Carmakal, chief technology officer at Mandiant Consulting, told CyberScoop Thursday evening.
May 27 to June 9, 2026
ShinyHunters exploited a zero-day vulnerability in PeopleTools.
Click on any entity below to view its context and source!
tactic
Extortion
From May 27 to June 9, 2026, the
ShinyHunters
extortion gang exploited a zero-day vulnerability in PeopleTools, PeopleSoft's underlying integrated development environment (IDE) and runtime platform, according to new research from Mandiant and the Google Threat Intelligence Group (GTIG).
attribution
Mandiant
From May 27 to June 9, 2026, the
ShinyHunters
extortion gang exploited a zero-day vulnerability in PeopleTools, PeopleSoft's underlying integrated development environment (IDE) and runtime platform, according to new research from Mandiant and the Google Threat Intelligence Group (GTIG).
attribution
the Google Threat Intelligence Group
From May 27 to June 9, 2026, the
ShinyHunters
extortion gang exploited a zero-day vulnerability in PeopleTools, PeopleSoft's underlying integrated development environment (IDE) and runtime platform, according to new research from Mandiant and the Google Threat Intelligence Group (GTIG).
attribution
PeopleTools
From May 27 to June 9, 2026, the
ShinyHunters
extortion gang exploited a zero-day vulnerability in PeopleTools, PeopleSoft's underlying integrated development environment (IDE) and runtime platform, according to new research from Mandiant and the Google Threat Intelligence Group (GTIG).
between May 27 and June 9
Threat actors exploited an Oracle Zero-Day vulnerability in the ShinyHunters malware targeting higher education institutions between May 27 and June 9.
Click on any entity below to view its context and source!
organisation
IP
Google said it spotted malicious activity, “consistent with the exploitation of CVE-2026-35273,” between May 27 and June 9, and notified more than 100 global orgs “whose IP addresses correlated with potentially vulnerable endpoints.
vulnerability
CVE-2026-35273
Google said it spotted malicious activity, “consistent with the exploitation of CVE-2026-35273,” between May 27 and June 9, and notified more than 100 global orgs “whose IP addresses correlated with potentially vulnerable endpoints.
general_metric
100 organisations
Google said it spotted malicious activity, “consistent with the exploitation of CVE-2026-35273,” between May 27 and June 9, and notified more than 100 global orgs “whose IP addresses correlated with potentially vulnerable endpoints.
organisation
Google
Google said it spotted malicious activity, “consistent with the exploitation of CVE-2026-35273,” between May 27 and June 9, and notified more than 100 global orgs “whose IP addresses correlated with potentially vulnerable endpoints.
Google's Mandiant
attributes
it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9.
May 27 to June 9
ShinyHunters exploited an Oracle zero-day in higher education institutions from May 27 to June 9.
2026/06/12
The hackers used a zero-day vulnerability in Oracle PeopleSoft to break into enterprise systems, steal data.
Click on any entity below to view its context and source!
organisation
PeopleSoft
One of the group’s latest victims in the PeopleSoft-linked attack is the University of Nottingham in the United Kingdom, where the
personal data of 450,000 students was leaked
just a couple of days ago.
“We have previously observed ShinyHunters target the education sector this year, however it’s possible this targeting is representative of the majority of exposed PeopleSoft instances belonging to the sector,” Carmakal said.
ShinyHunters used a zero-day vulnerability in Oracle's PeopleSoft software suite to steal data from potentially more than 100 organizations.
ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day.
The script parses
/etc/hosts
for internal PeopleSoft node hostnames, then sprays a hardcoded list of usernames and passwords against each one over SSH.
"
Oracle has confirmed that the zero-day vulnerability affects PeopleSoft Enterprise PeopleTools, versions 8.61 and 8.62, and has released
emergency mitigations
to address the flaw, with a patch coming soon.
The flaw,
CVE-2026-35273
, is a remote code execution bug in PeopleSoft Enterprise PeopleTools rated 9.8 out of 10.
organisation
the University of Nottingham
One of the group’s latest victims in the PeopleSoft-linked attack is the University of Nottingham in the United Kingdom, where the
personal data of 450,000 students was leaked
just a couple of days ago.
The University of Nottingham in the U.K. has confirmed that it was one of the fallen, having lost "a significant amount of data" from its student records system.
On its dark web leak site, ShinyHunters listed the University of Nottingham as a recent victim, alleging it possessed more than 40 GB of sensitive data.
On Wednesday, a day after ShinyHunters leaked the school’s data, the University of Nottingham
confirmed the breach
and Oracle
issued an out-of-band security alert
.
The University of Nottingham is one of the first confirmed victims.
organisation
Oracle
ShinyHunters used a zero-day vulnerability in Oracle's PeopleSoft software suite to steal data from potentially more than 100 organizations.
PeopleTools versions 8.61 and 8.62 are confirmed affected; Oracle says earlier unsupported versions are likely vulnerable too.
ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw.
Since the group caught this flaw before Oracle released a patch, they proceeded completely unhindered.
“Oracle released mitigations,” Carmakal wrote.
Oracle mitigates PeopleSoft zero-day exploited in data theft attacks.
Mandiant CTO Charles Carmakal
confirmed
the bug is being exploited in the wild; Oracle has not said whether it has seen exploitation.
victims
100 organizations
ShinyHunters used a zero-day vulnerability in Oracle's PeopleSoft software suite to steal data from potentially more than 100 organizations.
Security
ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day
University of Nottingham is first of many, Shiny tells The Reg
Data theft and extortion group ShinyHunters has exploited a critical Oracle PeopleSoft bug as a zero-day to compromise more than 100 organizations, including the
University of Nottingham
, across 300 vulnerable instances.
Oracle PeopleSoft RCE Flaw Used as Zero-Day in Ongoing ShinyHunters Campaign
ShinyHunters exploited a critical Oracle PeopleSoft zero-day to breach over 100 organizations, mostly universities, before a patch was available.
Related:
Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure
Of the more than 100 at-risk organizations contacted by Google, most were based in the U.S., and 68% happened to be involved in higher education.
Researchers are warning that cybercriminals exploited an Oracle PeopleSoft zero-day vulnerability and potentially infiltrated the networks of more than 100 organizations in an attack spree that largely impacted higher education.
Google said it alerted
more than 100 organizations
of potentially vulnerable endpoints in their environments, but it declined to confirm how many victims are compromised.
The notorious cybercrime group claims it hacked more than 100 organizations and started naming victims and publishing allegedly stolen data Tuesday.
In a
blog post
, researchers from Mandiant and GTIG said they alerted more than 100 organizations with potentially vulnerable endpoints.
Related:
Claude Fable 5 Doesn't Change the Mythos Security Story
With the zero-day, ShinyHunters claims to have compromised more than 300 PeopleSoft instances across more than 100 organizations.
A Google threat intelligence
report
published Thursday afternoon corroborated ShinyHunters’ claims to have compromised more than 100 organizations.
Sixty-eight percent of the more than 100 organizations Mandiant notified were universities and colleges, most of them in the United States.
Using this flaw, the threat actor allegedly stole data from 300 instances for over 100 organizations.
"Upon becoming aware of active scanning and exploitation, we initiated notifications to over 100 global organizations whose IP addresses correlated with potentially vulnerable endpoints," Mandiant reported.
Mandiant notified more than 100 organizations whose IP addresses matched vulnerable endpoints.
organisation
ShinyHunters
ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day.
Zero-day exploited in ShinyHunter data theft attacks
While Oracle has not stated that this vulnerability is actively exploited, its disclosure comes after
BleepingComputer first reported
that the ShinyHunters extortion gang was exploiting a PeopleSoft zero-day vulnerability to breach instances and steal data.
Swati Khandelwal
Jun 11, 2026
Vulnerability / Data Breach
The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private.
The cybercrime group behind this wave is UNC6240 or
ShinyHunters
.
ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw.
ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed.
Oracle PeopleSoft RCE Flaw Used as Zero-Day in Ongoing ShinyHunters Campaign
ShinyHunters exploited a critical Oracle PeopleSoft zero-day to breach over 100 organizations, mostly universities, before a patch was available.
organisation
SSH
The script parses
/etc/hosts
for internal PeopleSoft node hostnames, then sprays a hardcoded list of usernames and passwords against each one over SSH.
The script, named [victim]_fanout.sh, spreads over SSH by spraying a hardcoded list of usernames and passwords against internal hosts pulled from /etc/hosts, then drops a marker file named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT into PeopleSoft directories.
Next, they used MeshCentral's command line interface (CLI) to perform reconnaissance, a custom SSH credential spraying script to spread further into victims' environments, and the Zstandard compression algorithm to exfiltrate data en masse.
infrastructure
8.61
"
Oracle has confirmed that the zero-day vulnerability affects PeopleSoft Enterprise PeopleTools, versions 8.61 and 8.62, and has released
emergency mitigations
to address the flaw, with a patch coming soon.
Screenshot credit Hackread.com
Vulnerability Details
CVE-2026-35273 is an unauthenticated remote code execution bug that exists in the
Oracle PeopleSoft PeopleTools
(mainly versions 8.61 and 8.62)
PeopleTools versions 8.61 and 8.62 are confirmed affected; Oracle says earlier unsupported versions are likely vulnerable too.
Oracle lists PeopleTools 8.61 and 8.62 as affected and says earlier, unsupported versions are probably vulnerable too.
infrastructure
8.62
"
Oracle has confirmed that the zero-day vulnerability affects PeopleSoft Enterprise PeopleTools, versions 8.61 and 8.62, and has released
emergency mitigations
to address the flaw, with a patch coming soon.
Screenshot credit Hackread.com
Vulnerability Details
CVE-2026-35273 is an unauthenticated remote code execution bug that exists in the
Oracle PeopleSoft PeopleTools
(mainly versions 8.61 and 8.62)
PeopleTools versions 8.61 and 8.62 are confirmed affected; Oracle says earlier unsupported versions are likely vulnerable too.
Oracle lists PeopleTools 8.61 and 8.62 as affected and says earlier, unsupported versions are probably vulnerable too.
data_breach
40 GB
On its dark web leak site, ShinyHunters listed the University of Nottingham as a recent victim, alleging it possessed more than 40 GB of sensitive data.
A spokesperson for the cybercrime crew on Thursday told
The Register
that they exploited CVE-2026-35273 to break into the university’s PeopleSoft system and steal 40 GB of personal data and billing records belonging to hundreds of thousands of current and former students.
The leaked data reportedly includes 40 GB of PII and financial information belonging to students and university staff.
organisation
MeshCentral
Also visible were staging materials, including MeshCentral agents, and a defacement and credential spray…
— Michael R (@nahamike01)
June 10, 2026
How the Hackers Operated
Researchers found five staging IP addresses (142.11.200.186 to 142.11.200.190) running Python SimpleHTTP servers on port 8888 that the hackers used to store their malware.
They tried concealing their activity by naming their MeshCentral agents after Microsoft Azure services.
MeshCentral is legitimate open-source remote management software, which means the traffic blends into normal administrative activity and doesn’t trigger obvious alerts.
"
Mandiant's report also shared additional technical details about the attacks, saying the threat actors used the exposed staging servers to host HTTP services and utilized custom MeshCentral remote management agents to communicate with attacker-controlled infrastructure masquerading as Microsoft Azure services.
Those servers exposed the staging files: a shared .bash_history, custom MeshCentral remote-management agents disguised as Microsoft Azure binaries, and a lateral-movement script.
organisation
IP
Also visible were staging materials, including MeshCentral agents, and a defacement and credential spray…
— Michael R (@nahamike01)
June 10, 2026
How the Hackers Operated
Researchers found five staging IP addresses (142.11.200.186 to 142.11.200.190) running Python SimpleHTTP servers on port 8888 that the hackers used to store their malware.
Researcher @nahamike01 publicly flagged open directories on five sequential IP addresses, all running Python’s built-in HTTP server on port 8888.
Cybersecurity researcher "
Michael R
" found several exposed online directories containing attack-related tooling and shared the following IP addresses used in the attacks.
Mandiant then triaged five sequential IP addresses running Python's SimpleHTTP server on port 8888.
organisation
Microsoft Azure
They tried concealing their activity by naming their MeshCentral agents after Microsoft Azure services.
"
Mandiant's report also shared additional technical details about the attacks, saying the threat actors used the exposed staging servers to host HTTP services and utilized custom MeshCentral remote management agents to communicate with attacker-controlled infrastructure masquerading as Microsoft Azure services.
Those servers exposed the staging files: a shared .bash_history, custom MeshCentral remote-management agents disguised as Microsoft Azure binaries, and a lateral-movement script.
“The staging infrastructure hosted pre-configured Windows MeshCentral agent binaries disguised as Microsoft Azure services, specifically named
meshagent32-azure-ops.exe
,
meshagent64-azure-ops.exe
, and
meshagent64-v2.exe
.” reads the report.
These files were strategically named after safe Microsoft Azure services to bypass security filters and hide their true goal- opening a backdoor to a C2 server (
wss://azurenetfiles.net:443/agent.ashx
).
organisation
Mandiant
"
Mandiant's report also shared additional technical details about the attacks, saying the threat actors used the exposed staging servers to host HTTP services and utilized custom MeshCentral remote management agents to communicate with attacker-controlled infrastructure masquerading as Microsoft Azure services.
In a
blog post
, researchers from Mandiant and GTIG said they alerted more than 100 organizations with potentially vulnerable endpoints.
Sixty-eight percent of the more than 100 organizations Mandiant notified were universities and colleges, most of them in the United States.
Mandiant notified more than 100 organizations whose IP addresses matched vulnerable endpoints.
organisation
Cybersecurity
Cybersecurity researcher "
Michael R
" found several exposed online directories containing attack-related tooling and shared the following IP addresses used in the attacks.
organisation
Oracle PeopleSoft
Security
ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day
University of Nottingham is first of many, Shiny tells The Reg
Data theft and extortion group ShinyHunters has exploited a critical Oracle PeopleSoft bug as a zero-day to compromise more than 100 organizations, including the
University of Nottingham
, across 300 vulnerable instances.
On Tuesday, BleepingComputer learned that Oracle PeopleSoft was targeted in a wave of data theft attacks that left ransom notes purportedly from the ShinyHunters extortion gang.
Swati Khandelwal
Jun 11, 2026
Vulnerability / Data Breach
The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private.
The group’s targets were organisations using the Oracle PeopleSoft software.
Oracle PeopleSoft RCE Flaw Used as Zero-Day in Ongoing ShinyHunters Campaign.
organisation
University of Nottingham
Security
ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day
University of Nottingham is first of many, Shiny tells The Reg
Data theft and extortion group ShinyHunters has exploited a critical Oracle PeopleSoft bug as a zero-day to compromise more than 100 organizations, including the
University of Nottingham
, across 300 vulnerable instances.
University of Nottingham, one of ShinyHunters’ alleged victims, on Wednesday confirmed a
significant amount of student data was stolen
during a cyberattack after the threat group leaked some of the school’s data.
organisation
the
University of Nottingham
Security
ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day
University of Nottingham is first of many, Shiny tells The Reg
Data theft and extortion group ShinyHunters has exploited a critical Oracle PeopleSoft bug as a zero-day to compromise more than 100 organizations, including the
University of Nottingham
, across 300 vulnerable instances.
The
University of Nottingham
is among the first confirmed victims.
organisation
WebLogic
On successful login it copies a file named
README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT
into WebLogic and Process Scheduler directories, both as an extortion marker and as a propagation confirmation the operators could verify remotely.
Once inside, the attackers read WebLogic configurations (config.xml) and process scheduler files (psappsrv.cfg) to map out the internal network blueprints.
The researchers said the threat actors conducted reconnaissance on compromised instances, mapped PeopleSoft and WebLogic configurations, and used scripts to laterally move across internal systems using stolen or hardcoded credentials.
Then hunt for signs of an existing compromise:
WebLogic access logs showing external POST requests to /PSEMHUB/hub or /PSIGW/HttpListeningConnector.
organisation
BleepingComputer
Zero-day exploited in ShinyHunter data theft attacks
While Oracle has not stated that this vulnerability is actively exploited, its disclosure comes after
BleepingComputer first reported
that the ShinyHunters extortion gang was exploiting a PeopleSoft zero-day vulnerability to breach instances and steal data.
organisation
Vulnerability / Data Breach
Swati Khandelwal
Jun 11, 2026
Vulnerability / Data Breach
The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private.
organisation
Hackread.com
Screenshot credit Hackread.com
Vulnerability Details
CVE-2026-35273 is an unauthenticated remote code execution bug that exists in the
Oracle PeopleSoft PeopleTools
(mainly versions 8.61 and 8.62)
organisation
Vulnerability Details
Screenshot credit Hackread.com
Vulnerability Details
CVE-2026-35273 is an unauthenticated remote code execution bug that exists in the
Oracle PeopleSoft PeopleTools
(mainly versions 8.61 and 8.62)
organisation
Oracle PeopleSoft PeopleTools
Screenshot credit Hackread.com
Vulnerability Details
CVE-2026-35273 is an unauthenticated remote code execution bug that exists in the
Oracle PeopleSoft PeopleTools
(mainly versions 8.61 and 8.62)
The flaw is within Oracle PeopleSoft PeopleTools and has a CVSS base score of 9.8.
organisation
CVE-2026
A spokesperson for the cybercrime crew on Thursday told
The Register
that they exploited CVE-2026-35273 to break into the university’s PeopleSoft system and steal 40 GB of personal data and billing records belonging to hundreds of thousands of current and former students.
organisation
The Register
A spokesperson for the cybercrime crew on Thursday told
The Register
that they exploited CVE-2026-35273 to break into the university’s PeopleSoft system and steal 40 GB of personal data and billing records belonging to hundreds of thousands of current and former students.
organisation
CVE-2026-35273
CVE-2026-35273
is a 9.8 CVSS-rated vulnerability that allows remote, unauthenticated attackers with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools and fully take over the platform.
organisation
Oracle PeopleSoft’s Environment Management
The flaw,
CVE-2026-35273
(CVSS score of 9.8), is a remote code execution vulnerability in Oracle PeopleSoft’s Environment Management component, rated 9.8 out of 10.
infrastructure
142.11.200
142.11.200[.]186
142.11.200[.]187
142.11.200[.]188
142.11.200[.]189
142.11.200[.]190
108.174.202[.]99
176.120.22[.]24
Targeting the education sector
Mandiant
released a report
confirming that threat actors exploited the Oracle PeopleSoft CVE-2026-35273 vulnerability as a zero-day, primarily targeting organizations in the education sector.
infrastructure
108.174.202
142.11.200[.]186
142.11.200[.]187
142.11.200[.]188
142.11.200[.]189
142.11.200[.]190
108.174.202[.]99
176.120.22[.]24
Targeting the education sector
Mandiant
released a report
confirming that threat actors exploited the Oracle PeopleSoft CVE-2026-35273 vulnerability as a zero-day, primarily targeting organizations in the education sector.
infrastructure
176.120.22
142.11.200[.]186
142.11.200[.]187
142.11.200[.]188
142.11.200[.]189
142.11.200[.]190
108.174.202[.]99
176.120.22[.]24
Targeting the education sector
Mandiant
released a report
confirming that threat actors exploited the Oracle PeopleSoft CVE-2026-35273 vulnerability as a zero-day, primarily targeting organizations in the education sector.
organisation
ShinyHunter
Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks.
organisation
Breach Universities
ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities.
organisation
Suspicious
webshell files in WebLogic application directories
Unauthorized files or binaries staged in PSEMHUB transaction folders
Suspicious directories such as logs, persistantstorage, or scratchpad
Recently modified XML files that could be used to maintain persistence or trigger remote code execution after a restart
ShinyHunters recently targeted the education sector in a
massive cyberattack on Instructure Canvas
that allowed them to steal 280 million data records for students, teachers, and staff.
organisation
XML
webshell files in WebLogic application directories
Unauthorized files or binaries staged in PSEMHUB transaction folders
Suspicious directories such as logs, persistantstorage, or scratchpad
Recently modified XML files that could be used to maintain persistence or trigger remote code execution after a restart
ShinyHunters recently targeted the education sector in a
massive cyberattack on Instructure Canvas
that allowed them to steal 280 million data records for students, teachers, and staff.
data_breach
280 data records
webshell files in WebLogic application directories
Unauthorized files or binaries staged in PSEMHUB transaction folders
Suspicious directories such as logs, persistantstorage, or scratchpad
Recently modified XML files that could be used to maintain persistence or trigger remote code execution after a restart
ShinyHunters recently targeted the education sector in a
massive cyberattack on Instructure Canvas
that allowed them to steal 280 million data records for students, teachers, and staff.
organisation
PeopleTools
PeopleTools versions 8.61 and 8.62 are confirmed affected; Oracle says earlier unsupported versions are likely vulnerable too.
Apply Oracle's update for your PeopleTools version once you confirm it is available in My Oracle Support.
infrastructure
Windows
“The staging infrastructure hosted pre-configured Windows MeshCentral agent binaries disguised as Microsoft Azure services, specifically named
meshagent32-azure-ops.exe
,
meshagent64-azure-ops.exe
, and
meshagent64-v2.exe
.” reads the report.
organisation
POST
Then hunt for signs of an existing compromise:
WebLogic access logs showing external POST requests to /PSEMHUB/hub or /PSIGW/HttpListeningConnector.
Then hunt: check WebLogic access logs for external POST requests to those paths, scan for unexpected JSP files under the PSEMHUB.war directory, look for directories named
logs
,
persistantstorage
, or
scratchpad
under PSEMHUB paths, and monitor for outbound SMB traffic on port 445 from PeopleSoft hosts to external destinations.
organisation
ERP
PeopleSoft is an enterprise resource planning (ERP) application suite used for things like payroll, supply chain management, human resources (HR), and student administration.
A server-side zero-day in on-premises ERP software is a step up from that, aimed at the same data-rich targets.
organisation
ShinyHunters Target Universities
ShinyHunters Target Universities in Oracle PeopleSoft Zero-Day Attack.
organisation
PII
The leaked data reportedly includes 40 GB of PII and financial information belonging to students and university staff.
organisation
SMB
They should also watch out for Server-Side Request Forgery (SSRF) in their access logs and block unusual port 445 SMB traffic leaving their systems.
Then hunt: check WebLogic access logs for external POST requests to those paths, scan for unexpected JSP files under the PSEMHUB.war directory, look for directories named
logs
,
persistantstorage
, or
scratchpad
under PSEMHUB paths, and monitor for outbound SMB traffic on port 445 from PeopleSoft hosts to external destinations.
data_breach
445 SMB traffic
They should also watch out for Server-Side Request Forgery (SSRF) in their access logs and block unusual port 445 SMB traffic leaving their systems.
organisation
JSP
Then hunt: check WebLogic access logs for external POST requests to those paths, scan for unexpected JSP files under the PSEMHUB.war directory, look for directories named
logs
,
persistantstorage
, or
scratchpad
under PSEMHUB paths, and monitor for outbound SMB traffic on port 445 from PeopleSoft hosts to external destinations.
organisation
IdP
This attack shows that traditional perimeter security and IdP-level authentication are necessary, but not sufficient.
organisation
Modern ERP
Modern ERP security requires a layered approach that combines preventive controls, continuous monitoring, and visibility into user activity.
organisation
Google
Related:
Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure
Of the more than 100 at-risk organizations contacted by Google, most were based in the U.S., and 68% happened to be involved in higher education.
Google said it alerted
more than 100 organizations
of potentially vulnerable endpoints in their environments, but it declined to confirm how many victims are compromised.
reads the
report
published by Google.
infrastructure
Ivanti
Related:
Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure
Of the more than 100 at-risk organizations contacted by Google, most were based in the U.S., and 68% happened to be involved in higher education.
organisation
Canvas
ShinyHunters has lately leaned on vishing, stolen tokens, and weak access controls to steal data from SaaS and education platforms, from
Salesforce customers
to
Canvas
.
Last September, threat actors tied to the group breached Instructure, an edtech company known for its widely used Canvas learning management platform.
organisation
Mandiant Chief Technology
Google-owned Mandiant Chief Technology Officer Charles Carmakal, in a brief LinkedIn post on Thursday,
warned
that PeopleSoft was one of two zero-day vulnerabilities “actively being exploited in the wild.”
organisation
Oracle E-Business Suite
The attacks come less than a year after the Clop ransomware group exploited a
zero-day in Oracle E-Business Suite
that affected dozens of victims.
organisation
CLI
Next, they used MeshCentral's command line interface (CLI) to perform reconnaissance, a custom SSH credential spraying script to spread further into victims' environments, and the Zstandard compression algorithm to exfiltrate data en masse.
They then used MeshCentral’s CLI tool
meshctrl.js
to run commands on compromised endpoints: mapping Oracle PeopleSoft configurations, reading process scheduler config files, parsing internal host tables, and inspecting WebLogic XML configs to identify additional targets inside each victim network.
organisation
Zstandard
Next, they used MeshCentral's command line interface (CLI) to perform reconnaissance, a custom SSH credential spraying script to spread further into victims' environments, and the Zstandard compression algorithm to exfiltrate data en masse.
organisation
WebLogic XML
They then used MeshCentral’s CLI tool
meshctrl.js
to run commands on compromised endpoints: mapping Oracle PeopleSoft configurations, reading process scheduler config files, parsing internal host tables, and inspecting WebLogic XML configs to identify additional targets inside each victim network.
organisation
the Environment Management Hub
More specifically, the vulnerability is located in the Environment Management Hub (EMHub), a backend service that tracks and manages agents across PeopleSoft environments.
Just network access to the Environment Management Hub endpoint and you can take over the server.
If you run PeopleSoft with the Environment Management Hub reachable from outside, that is your exposure, and the immediate move is to lock those endpoints down.
organisation
Trend Micro's
In an email to Dark Reading, Dustin Childs, head of threat awareness for Trend Micro's Zero Day Initiative, characterizes the exploitation as "limited," though notes that the investigation by TrendAI, Trend Micro's enterprise security division, is still ongoing.
organisation
Bug Bounty Research Triggers
Related:
Bug Bounty Research Triggers ServiceNow Security Alert
In the PeopleSoft attacks, Mandiant and GTIG researchers noted that "In several instances we have identified web application firewalls (WAFs) protecting otherwise vulnerable organizations."
organisation
Microsoft Azure NetApp Files
The domain was chosen to look like Microsoft Azure NetApp Files.
organisation
the EMHub Service
“
Endpoint Access Restrictions:
If you cannot disable the EMHub Service, immediately block external network access to the sensitive endpoints
/PSEMHUB/*
(specifically
/PSEMHUB/hub
) and
/PSIGW/HttpListeningConnector
at the network perimeter or firewall level.
organisation
Outbound SMB
Outbound SMB traffic on port 445 from PeopleSoft hosts to external destinations, which the exploit chain may use to capture machine-account NetNTLM hashes.
organisation
NetNTLM
Outbound SMB traffic on port 445 from PeopleSoft hosts to external destinations, which the exploit chain may use to capture machine-account NetNTLM hashes.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, ShinyHunters)
organisation
Oracle PeopleSoft Enterprise Applications
Oracle PeopleSoft Enterprise Applications customers may also be affected by this vulnerability," reads a new Oracle advisory.
organisation
SnowFlake
The group has been linked to numerous high-profile attacks targeting
SnowFlake
,
Salesforce
, and
third-party integration providers
over the past year.
organisation
Unexpected
As part of its guidance, Mandiant advised organizations to restrict access to vulnerable PeopleSoft endpoints, review logs for suspicious requests targeting
/PSEMHUB/
and
/PSIGW/HttpListeningConnector
, and inspect servers for signs of compromise, including:
Unexpected .jsp
Unexpected .jsp files under the PSEMHUB.war web application directory, or odd folders named logs, persistantstorage, or scratchpad under the PSEMHUB paths.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
organisation
the Updates Environment Management
The vulnerability sits in the Updates Environment Management component, the piece behind the Environment Management Hub (PSEMHUB).
organisation
the Environment Management Hub (PSEMHUB
The vulnerability sits in the Updates Environment Management component, the piece behind the Environment Management Hub (PSEMHUB).
organisation
doc root's
Recently changed .xml files under the web doc root's envmetadata/data/environment, which can be abused for XMLDecoder persistence that fires on the next restart.
organisation
XMLDecoder
Recently changed .xml files under the web doc root's envmetadata/data/environment, which can be abused for XMLDecoder persistence that fires on the next restart.
Tactical Metrics
Metrics
infrastructure
8.61
Software Version
Click for context!
Screenshot credit Hackread.com
Vulnerability Details
CVE-2026-35273 is an unauthenticated remote code execution bug that exists in the
Oracle PeopleSoft PeopleTools
(mainly versions 8.61 and 8.62)
PeopleTools versions 8.61 and 8.62 are confirmed affected; Oracle says earlier unsupported versions are likely vulnerable too.
"
Oracle has confirmed that the zero-day vulnerability affects PeopleSoft Enterprise PeopleTools, versions 8.61 and 8.62, and has released
emergency mitigations
to address the flaw, with a patch coming soon.
Oracle lists PeopleTools 8.61 and 8.62 as affected and says earlier, unsupported versions are probably vulnerable too.
Metrics
infrastructure
8.62
Software Version
Screenshot credit Hackread.com
Vulnerability Details
CVE-2026-35273 is an unauthenticated remote code execution bug that exists in the
Oracle PeopleSoft PeopleTools
(mainly versions 8.61 and 8.62)
PeopleTools versions 8.61 and 8.62 are confirmed affected; Oracle says earlier unsupported versions are likely vulnerable too.
"
Oracle has confirmed that the zero-day vulnerability affects PeopleSoft Enterprise PeopleTools, versions 8.61 and 8.62, and has released
emergency mitigations
to address the flaw, with a patch coming soon.
Oracle lists PeopleTools 8.61 and 8.62 as affected and says earlier, unsupported versions are probably vulnerable too.
Metrics
data_breach
40
Gb
The leaked data reportedly includes 40 GB of PII and financial information belonging to students and university staff.
On its dark web leak site, ShinyHunters listed the University of Nottingham as a recent victim, alleging it possessed more than 40 GB of sensitive data.
A spokesperson for the cybercrime crew on Thursday told
The Register
that they exploited CVE-2026-35273 to break into the university’s PeopleSoft system and steal 40 GB of personal data and billing records belonging to hundreds of thousands of current and former students.
Metrics
data_breach
445
Smb Traffic
They should also watch out for Server-Side Request Forgery (SSRF) in their access logs and block unusual port 445 SMB traffic leaving their systems.
Metrics
victims
100
Organizations
Researchers are warning that cybercriminals exploited an Oracle PeopleSoft zero-day vulnerability and potentially infiltrated the networks of more than 100 organizations in an attack spree that largely impacted higher education.
Google said it alerted
more than 100 organizations
of potentially vulnerable endpoints in their environments, but it declined to confirm how many victims are compromised.
The notorious cybercrime group claims it hacked more than 100 organizations and started naming victims and publishing allegedly stolen data Tuesday.
Related:
Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure
Of the more than 100 at-risk organizations contacted by Google, most were based in the U.S., and 68% happened to be involved in higher education.
ShinyHunters used a zero-day vulnerability in Oracle's PeopleSoft software suite to steal data from potentially more than 100 organizations.
In a
blog post
, researchers from Mandiant and GTIG said they alerted more than 100 organizations with potentially vulnerable endpoints.
Related:
Claude Fable 5 Doesn't Change the Mythos Security Story
With the zero-day, ShinyHunters claims to have compromised more than 300 PeopleSoft instances across more than 100 organizations.
Security
ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day
University of Nottingham is first of many, Shiny tells The Reg
Data theft and extortion group ShinyHunters has exploited a critical Oracle PeopleSoft bug as a zero-day to compromise more than 100 organizations, including the
University of Nottingham
, across 300 vulnerable instances.
A Google threat intelligence
report
published Thursday afternoon corroborated ShinyHunters’ claims to have compromised more than 100 organizations.
Sixty-eight percent of the more than 100 organizations Mandiant notified were universities and colleges, most of them in the United States.
Oracle PeopleSoft RCE Flaw Used as Zero-Day in Ongoing ShinyHunters Campaign
ShinyHunters exploited a critical Oracle PeopleSoft zero-day to breach over 100 organizations, mostly universities, before a patch was available.
Using this flaw, the threat actor allegedly stole data from 300 instances for over 100 organizations.
"Upon becoming aware of active scanning and exploitation, we initiated notifications to over 100 global organizations whose IP addresses correlated with potentially vulnerable endpoints," Mandiant reported.
Mandiant notified more than 100 organizations whose IP addresses matched vulnerable endpoints.
Metrics
infrastructure
Ivanti
Affected Product
Related:
Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure
Of the more than 100 at-risk organizations contacted by Google, most were based in the U.S., and 68% happened to be involved in higher education.
Metrics
infrastructure
Windows
Affected Product
“The staging infrastructure hosted pre-configured Windows MeshCentral agent binaries disguised as Microsoft Azure services, specifically named
meshagent32-azure-ops.exe
,
meshagent64-azure-ops.exe
, and
meshagent64-v2.exe
.” reads the report.
Metrics
infrastructure
1.1.59
Software Version
On May 27 at 22:14 UTC, the attackers installed MeshCentral version 1.1.59.
Metrics
infrastructure
142.11.200
Software Version
142.11.200[.]186
142.11.200[.]187
142.11.200[.]188
142.11.200[.]189
142.11.200[.]190
108.174.202[.]99
176.120.22[.]24
Targeting the education sector
Mandiant
released a report
confirming that threat actors exploited the Oracle PeopleSoft CVE-2026-35273 vulnerability as a zero-day, primarily targeting organizations in the education sector.
Metrics
infrastructure
108.174.202
Software Version
142.11.200[.]186
142.11.200[.]187
142.11.200[.]188
142.11.200[.]189
142.11.200[.]190
108.174.202[.]99
176.120.22[.]24
Targeting the education sector
Mandiant
released a report
confirming that threat actors exploited the Oracle PeopleSoft CVE-2026-35273 vulnerability as a zero-day, primarily targeting organizations in the education sector.
Metrics
infrastructure
176.120.22
Software Version
142.11.200[.]186
142.11.200[.]187
142.11.200[.]188
142.11.200[.]189
142.11.200[.]190
108.174.202[.]99
176.120.22[.]24
Targeting the education sector
Mandiant
released a report
confirming that threat actors exploited the Oracle PeopleSoft CVE-2026-35273 vulnerability as a zero-day, primarily targeting organizations in the education sector.
Metrics
data_breach
280,000,000
Data Records
webshell files in WebLogic application directories
Unauthorized files or binaries staged in PSEMHUB transaction folders
Suspicious directories such as logs, persistantstorage, or scratchpad
Recently modified XML files that could be used to maintain persistence or trigger remote code execution after a restart
ShinyHunters recently targeted the education sector in a
massive cyberattack on Instructure Canvas
that allowed them to steal 280 million data records for students, teachers, and staff.
Intelligence Sources
BleepingComputer
2026-06-11
Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
BleepingComputer
The Register - Cybercrime
2026-06-11
ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day
The Register - Cybercrime
The Hacker News
2026-06-11
Dark Reading
2026-06-12
HackRead
2026-06-12
Security Affairs
2026-06-12
The Register - Cybercrime
2026-06-11
ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day
The Register - Cybercrime
Security Affairs
2026-06-12
Dark Reading
2026-06-12
CyberScoop
2026-06-12
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-27T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
63x
organisation
Identified Entity
PeopleSoft
entity
17x
timeline
Temporal Reference
June 10, 2026
How the Hackers Operated
Researchers
date
9x
tactic
Cyber Operation Type
Defacement
tactic
6x
infrastructure
Software Version
8.61
version
6x
attribution
Attributing Entity
Mandiant
authority
3x
tactic
MITRE ATT&CK Technique
T1059.006 - Python
technique
3x
general metric
%
68
%
3x
industry
Targeted Sector
Education
sector
2x
source region
Origin Country
United States
country
2x
general metric
Port
8,888
port
2x
infrastructure
Affected Product
Ivanti
software
2x
target region
Target Country
United Kingdom
country
Contextual Telemetry
Context Block
18 METRICS
general metric
Students
450,000
students
vulnerability
Exploited CVE
CVE-2026-35273
cve
vulnerability
CVSS Score
10
score
general metric
Peopletools
9
peopletools
data breach
Gb
40
gb
data breach
Smb Traffic
445
smb traffic
general metric
Organisations
100
organisations
victims
Organizations
100
organizations
general metric
Tools
40
tools
general metric
Hours
24
hours
general metric
Claude Fable
5
claude fable
general metric
Peoplesoft Instances
300
peoplesoft instances
general metric
Cve-2026
35,273
cve-2026
general metric
Rated Vulnerability
10
rated vulnerability
campaign
Campaign
Campaign
ShinyHunters
operation
general metric
Unique Email Addresses
455,000
unique email addresses
data breach
Data Records
280,000,000
data records
general metric
Khandelwal Jun
11
khandelwal jun
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.