INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ShinyHunters Exploits Oracle Zero-Day in Higher Ed Rampage

| 2026-06-12 14:06 CRITICAL HIGH
Executive Summary AI-generated
The ShinyHunters extortion gang has exploited a zero-day vulnerability in Oracle's PeopleSoft software suite to steal data from potentially more than 100 organizations. This attack, which began on May 27 and ended on June 9, targeted the Education Sector, with several higher education institutions falling victim. The group used a custom SSH credential spraying script to spread further into victims' environments, followed by a reconnaissance phase using MeshCentral's command line interface CLI to gather information. They then exfiltrated data using the Zstandard compression algorithm and performed remote code execution without authentication required. This exploit has been assigned a label CVE-2026-35273 with a critical 9.8 CVSS score, making it a high-risk threat for organizations relying on Oracle's PeopleSoft software suite.
Technical Mitigations AI-generated
* Regularly update and patch Oracle's PeopleSoft software suite: Ensure that all versions of the application are up-to-date with the latest security patches, as these fixes often include exploits for previously discovered vulnerabilities. * Implement a robust incident response plan: Establish a clear process for responding to incidents like this one, including procedures for identifying, containing, and mitigating attacks. This will help minimize damage and prevent further exploitation of the same vulnerability. * Use secure authentication mechanisms: Ensure that all systems and applications use strong authentication protocols, such as multi-factor authentication (MFA), to prevent unauthorized access even if an attacker gains remote code execution through a zero-day exploit like this one. * Monitor for suspicious activity and implement network segmentation: Regularly monitor system logs and network traffic for signs of unusual activity. Implement network segmentation to limit the spread of malware and data exfiltration, making it more difficult for attackers to move laterally within an organization's network. * Educate users about phishing and social engineering tactics: Remind employees that they should be cautious when clicking on links or providing sensitive information online, as these can be used by attackers to gain access to systems. Encourage them to verify the authenticity of emails and messages before responding.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign ShinyHuntersCampaign ShinyHunters CVE-2026-35273CVE-2026-35273
Target & Sectors
NORTH_AMERICA NORTH_AMERICA educationeducation governmentgovernment technologytechnology
Incident Timeline
‎May 27, 2026
ShinyHunters exploited a previously unknown Oracle zero-day in higher education attacks.
‎May 27
ShinyHunters exploited CVE-2026-35273 in Oracle PeopleSoft PeopleTools version 1.1.59 to target higher education organizations on May 27.
vulnerability CVE-2026-35273
organisation Oracle PeopleSoft PeopleTools
organisation Mandiant
organisation CVE-2026
infrastructure 1.1.59
organisation UTC
‎between May 27, 2026
ShinyHunters exploited CVE-2026-35273 in the Environment Management component of a higher education institution between May 27, 2026.
vulnerability CVE-2026-35273
vulnerability CVSS 9.8
tactic Remote Code Execution
‎June 9, 2026
ShinyHunters exploited CVE-2026-35273 in a higher education attack using Remote Code Execution.
vulnerability CVE-2026-35273
vulnerability CVSS 9.8
tactic Remote Code Execution
‎June 9
Threat actors exploited an Oracle Zero-Day in the Higher Ed sector to gain unauthorized access.
‎June 10, 2026
ShinyHunters exploited an Oracle Zero-Day in the targeted Higher Ed entity's systems.
organisation Oracle’s
‎10 June 2026
Threat actors exploited an Oracle Zero-Day vulnerability in the company's database.
‎June 10
Threat actors exploited an Oracle Zero-Day vulnerability in the company's database, targeting higher education institutions on June 10.
‎Jun 11, 2026
ShinyHunters exploited a previously unknown Oracle zero-day in higher education attacks.
‎June 11
Mandiant and Google's Threat Intelligence Group analyzed an active ShinyHunters campaign on June 11.
attribution Mandiant
attribution Google’s Threat Intelligence Group
‎between 27 May and 9 June
ShinyHunters exploited a critical Oracle zero-day flaw (CVE-2026-35273, CVSS 9.8) in higher education networks between May 27 and June 9.
vulnerability CVE-2026-35273
vulnerability CVSS 9.8
‎2026/06/12
ShinyHunters exploited an Oracle Zero-Day in the PeopleSoft ERP system to launch attacks on higher education institutions.
organisation ERP
industry Technology
organisation Mandiant Consulting
organisation CyberScoop
‎May 27 to June 9, 2026
ShinyHunters exploited a zero-day vulnerability in PeopleTools.
tactic Extortion
attribution Mandiant
attribution the Google Threat Intelligence Group
attribution PeopleTools
‎between May 27 and June 9
Threat actors exploited an Oracle Zero-Day vulnerability in the ShinyHunters malware targeting higher education institutions between May 27 and June 9.
organisation IP
vulnerability CVE-2026-35273
general_metric 100 organisations
organisation Google
‎May 27 to June 9
ShinyHunters exploited an Oracle zero-day in higher education institutions from May 27 to June 9.
‎2026/06/12
The hackers used a zero-day vulnerability in Oracle PeopleSoft to break into enterprise systems, steal data.
organisation PeopleSoft
organisation the University of Nottingham
organisation Oracle
victims 100 organizations
organisation ShinyHunters
organisation SSH
infrastructure 8.61
infrastructure 8.62
data_breach 40 GB
organisation MeshCentral
organisation IP
organisation Microsoft Azure
organisation Mandiant
organisation Cybersecurity
organisation Oracle PeopleSoft
organisation University of Nottingham
organisation the University of Nottingham
organisation WebLogic
organisation BleepingComputer
organisation Vulnerability / Data Breach
organisation Hackread.com
organisation Vulnerability Details
organisation Oracle PeopleSoft PeopleTools
organisation CVE-2026
organisation The Register
organisation CVE-2026-35273
organisation Oracle PeopleSoft’s Environment Management
infrastructure 142.11.200
infrastructure 108.174.202
infrastructure 176.120.22
organisation ShinyHunter
organisation Breach Universities
organisation Suspicious
organisation XML
data_breach 280 data records
organisation PeopleTools
infrastructure Windows
organisation POST
organisation ERP
organisation ShinyHunters Target Universities
organisation PII
organisation SMB
data_breach 445 SMB traffic
organisation JSP
organisation IdP
organisation Modern ERP
organisation Google
infrastructure Ivanti
organisation Canvas
organisation Mandiant Chief Technology
organisation Oracle E-Business Suite
organisation CLI
organisation Zstandard
organisation WebLogic XML
organisation the Environment Management Hub
organisation Trend Micro's
organisation Bug Bounty Research Triggers
organisation Microsoft Azure NetApp Files
organisation the EMHub Service
organisation Outbound SMB
organisation NetNTLM
organisation SecurityAffairs
organisation Oracle PeopleSoft Enterprise Applications
organisation SnowFlake
organisation Unexpected
organisation EDR
organisation the Updates Environment Management
organisation the Environment Management Hub (PSEMHUB
organisation doc root's
organisation XMLDecoder
Tactical Metrics
Metrics
infrastructure
‎8.61
Software Version
Metrics
infrastructure
‎8.62
Software Version
Metrics
data_breach
40
Gb
Metrics
data_breach
445
Smb Traffic
Metrics
victims
100
Organizations
Metrics
infrastructure
‎Ivanti
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎1.1.59
Software Version
Metrics
infrastructure
‎142.11.200
Software Version
Metrics
infrastructure
‎108.174.202
Software Version
Metrics
infrastructure
‎176.120.22
Software Version
Metrics
data_breach
280,000,000
Data Records