AI Stories on SHORT INFO are generated & curated with AI
unverified 01 Jul, 02:09

Oracle PeopleSoft zero-day CVE-2026-35273 ShinyHunters universities breach

If your university runs Oracle PeopleSoft $ORCL, student and staff records may already be exposed. The ShinyHunters group exploited a critical zero-day (CVE-2026-35273, rated 9.8) from May 27, weeks before Oracle's June 10 patch. Of 100+ flagged organizations, 68% were universiti

If your university or college runs Oracle PeopleSoft $ORCL, its student and staff records may already have been exposed. Security researchers have confirmed that a criminal group tracked as ShinyHunters exploited a critical flaw in the software for nearly two weeks before any fix existed. The vulnerability, CVE-2026-35273, sits in Oracle's PeopleTools platform and is rated 9.8 out of 10 in severity. It requires no login and no action from a victim: an attacker only needs network access over HTTP to take control of the server. Google's Mandiant dates the exploitation to between May 27 and June 9. Oracle did not publish its advisory and out-of-band patch until June 10, meaning the bug was a true zero-day the entire time. The campaign hit education hardest. Mandiant notified more than 100 organizations whose systems matched vulnerable endpoints, and 68 percent of them were in higher education, most located in the United States. Once inside, the attackers deployed tools to move across internal networks and left behind a marker file announcing the breach. CISA has since warned that the same flaw is being used in ransomware attacks. Any institution still running an unpatched PeopleSoft environment is exposed to theft from its payroll, enrollment and personnel systems.

Published on
FacebookXBlueskyThreads