AI Stories on SHORT INFO are generated & curated with AI
unverified 28 Jun, 07:10

Oracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunters hits US universities

Dozens of US universities may have had personal data stolen via a flaw in Oracle $ORCL PeopleSoft, the HR and records software many schools run. ShinyHunters exploited the bug (CVE-2026-35273, CVSS 9.8) as a zero-day before Oracle's June 10 fix. Mandiant says most victims were sc

Dozens of US universities may have had personal data stolen through a critical vulnerability in Oracle PeopleSoft $ORCL, the human-resources, finance, and student-records platform that many large institutions run. The flaw, tracked as CVE-2026-35273 and rated 9.8 out of 10 on the CVSS severity scale, lets an attacker run code on a server without logging in. According to Mandiant, the data-theft group ShinyHunters exploited the bug as a zero-day between late May and early June, before Oracle issued an emergency advisory on June 10. More than 100 organizations were notified, and about 68 percent of them were in higher education, most in the United States. The attackers targeted PeopleSoft web endpoints to gain remote code execution, then deployed remote-management software to keep persistent access. ShinyHunters has begun publishing stolen records on its leak site for victims that did not respond. Education systems are a recurring target because they hold large volumes of sensitive records, including names, identification numbers, and financial details, and often run complex enterprise software that is slow to patch. The affected versions are PeopleTools 8.61 and 8.62. Oracle has released mitigations and a full patch, and administrators are urged to apply the update and check for signs of compromise such as unexpected remote-access agents. For students, staff, and alumni at affected schools, the practical risk is identity fraud, so watching financial accounts and credit activity is a reasonable precaution. Source: Mandiant and Oracle security advisory, reported via BleepingComputer and The Hacker News.

Published on
XThreadsFacebookBluesky