Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Oracle PeopleSoft Vulnerability Exploited by ShinyHunters

Oracle PeopleSoft Vulnerability Exploited by ShinyHunters

Posted on June 13, 2026 By CWS

Google has verified that a critical vulnerability in PeopleSoft, addressed by Oracle this week, has been actively exploited by the cybercriminal group ShinyHunters. This exploitation involved a zero-day attack to extract sensitive information from various organizations.

Details of the PeopleSoft Vulnerability

Oracle issued an urgent advisory regarding CVE-2026-35273, a severe unauthenticated remote code execution vulnerability affecting PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62, along with PeopleSoft Enterprise Applications. Although Oracle has provided interim mitigations, full patches have yet to be released.

PeopleSoft is a widely utilized enterprise resource planning (ERP) software suite that supports multiple organizational functions such as human resources, finance, and supply chain management. Despite its broad usage across sectors, the ShinyHunters’ focus appears to have been the education industry, with the University of Nottingham in the UK being the first confirmed victim.

Extent and Impact of Exploitation

Between May 27 and June 9, Mandiant and the Google Threat Intelligence Group (GTIG) detected activities linked to the exploitation of this zero-day vulnerability. The campaign, attributed to the ShinyHunters group, known as UNC6240, has seen significant targeting of higher education institutions, especially within the United States.

Google has alerted over 100 international organizations about potential vulnerabilities, noting that 68% are in the higher education sector. While some organizations successfully thwarted the attacks, others experienced system breaches and data theft.

ShinyHunters’ Attack Strategy and Consequences

ShinyHunters reportedly targeted approximately 300 PeopleSoft instances, impacting around 100 organizations. The attackers employed customized MeshCentral agents disguised as legitimate cloud services for executing administrative commands and spreading a specialized lateral movement and defacement script, leading to data leaks.

Google has provided detailed guidance on remediation measures and shared technical insights on the attack methodologies and indicators of compromise (IoCs). However, Oracle has yet to comment on the exploitation reports.

TrendAI, part of Trend Micro’s enterprise division, credited with reporting the vulnerability, stated that instances of exploitation remain limited, though their investigation continues.

As vulnerabilities like these pose significant risks, organizations are urged to implement Oracle’s recommended security measures promptly to protect their systems and data.

Security Week News Tags:Cybersecurity, data breach, Exploitation, Google, higher education, Mandiant, Oracle, PeopleSoft, ShinyHunters, Vulnerability, zero-day

Post navigation

Previous Post: LangGraph Vulnerabilities Risk Remote Code Execution
Next Post: Access to Anthropic AI Models Restricted by U.S. Government

Related Posts

Critical Vulnerability Patched in jsPDF Critical Vulnerability Patched in jsPDF Security Week News
Apple Blocks 2 Million App Store Apps for Security in 2025 Apple Blocks 2 Million App Store Apps for Security in 2025 Security Week News
Critical Dolby Vulnerability Patched in Android Critical Dolby Vulnerability Patched in Android Security Week News
Researchers Earn 0,000 for L1TF Exploit Leaking Data From Public Cloud Researchers Earn $150,000 for L1TF Exploit Leaking Data From Public Cloud Security Week News
North Korea’s Fake Recruiters Feed Stolen Data to IT Workers North Korea’s Fake Recruiters Feed Stolen Data to IT Workers Security Week News
Hack Targets French Government Messaging Platform Hack Targets French Government Messaging Platform Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Highlights Critical Security Flaws in Artifactory and RouterOS
  • VLC Media Player Security Flaws Pose Serious Risks
  • Enhancing Security: Tackling Cloud Supply-Chain Threats
  • AI-Driven Cyber Threats Demand Swift Security Upgrades
  • BlueMoon Exploit Kit Targets Chrome and Windows Zero-Days

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Highlights Critical Security Flaws in Artifactory and RouterOS
  • VLC Media Player Security Flaws Pose Serious Risks
  • Enhancing Security: Tackling Cloud Supply-Chain Threats
  • AI-Driven Cyber Threats Demand Swift Security Upgrades
  • BlueMoon Exploit Kit Targets Chrome and Windows Zero-Days

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark