SECURITYTHE HACKER NEWS
ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
ShinyHunters exploited an unpatched Oracle PeopleSoft zero-day (CVE-2026-35273) to breach enterprise systems, targeting universities most severely. Google's Mandiant linked the attacks to UNC6240, with activity occurring between May 27 and June 9, just one day before Oracle released its security advisory on June 10.
Mentioned
Related Signal
Adjacent reporting
- Cisco warns of unpatched SD-WAN zero-day exploited in attacks
- Adobe rolls out emergency fix for Acrobat, Reader zero-day flaw
- Yet another Cisco SD-WAN 0-day under attack, and no patch in sight
- Cisco customers encounter another SD-WAN zero-day under attack
- Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
- Fortinet Issues Emergency Patch for FortiClient Zero-Day