Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ShinyHunters Exploit Oracle Zero-Day to Target Universities

ShinyHunters Exploit Oracle Zero-Day to Target Universities

Posted on June 13, 2026 By CWS

The ShinyHunters cybercriminal group has capitalized on a newly discovered security flaw in Oracle PeopleSoft to infiltrate enterprise systems, pilfer sensitive data, and demand ransom. Higher education institutions have been most affected by this breach.

Understanding the Exploit

According to Google’s Mandiant, the group identified as UNC6240 conducted activities from May 27 to June 9. Oracle’s advisory was published on June 10, confirming the flaw was exploited as a zero-day vulnerability during this period. The identified flaw, CVE-2026-35273, is a remote code execution issue in PeopleSoft Enterprise PeopleTools, with a critical severity score of 9.8 out of 10.

This vulnerability allows attackers to assume control of servers through network access over HTTP without requiring user credentials or interaction. Systems using PeopleSoft with externally accessible Environment Management Hubs are particularly at risk, necessitating immediate security measures to restrict endpoint access.

Technical Details and Implications

The vulnerability resides in the Updates Environment Management component, specifically affecting PeopleTools versions 8.61 and 8.62. Oracle has also indicated that older, unsupported versions may be susceptible. The flaw was initially reported by researchers from TrendAI Zero Day Initiative and TrendAI Research.

Mandiant’s Chief Technology Officer, Charles Carmakal, confirmed active exploitation of this bug. However, Oracle has yet to provide a comprehensive fix. The current focus is on mitigating the risk by disabling the Environment Management Hub service or limiting external access to certain endpoints.

Impact and Response

The breach has exposed multiple vulnerabilities due to the attackers leaving their own infrastructure open. Mandiant found five servers running Python’s SimpleHTTP server on port 8888, which displayed sensitive staging files.

Approximately 100 organizations have been notified by Mandiant, with 68% belonging to the higher education sector, predominantly in the United States. Some institutions successfully blocked the attack, while others were compromised, leading to data leaks.

The University of Nottingham confirmed a breach, with Have I Been Pwned documenting around 455,000 unique email addresses leaked. This data includes personal information such as names, addresses, and other sensitive details.

Preventive Measures and Future Outlook

Oracle advises disabling or removing the Environment Management Hub service to mitigate risks. Additionally, further measures include monitoring WebLogic access logs for suspicious activity and applying Oracle’s updates when available.

As ShinyHunters continue to target high-value data sources, organizations must bolster cybersecurity defenses against potential ERP software exploitation. The group’s evolving tactics pose ongoing threats, suggesting the need for vigilant monitoring and proactive security strategies.

The Hacker News Tags:CVE-2026-35273, Cybersecurity, data breach, Mandiant, Oracle, PeopleSoft, ShinyHunters, Universities, Vulnerability, zero-day

Post navigation

Previous Post: Arch Linux AUR Packages Hit by Massive Supply Chain Attack
Next Post: Alert Fatigue: A Growing Security Challenge

Related Posts

Chrome 0-Day, Data Wipers, Misused Tools and Zero-Click iPhone Attacks Chrome 0-Day, Data Wipers, Misused Tools and Zero-Click iPhone Attacks The Hacker News
5 Ways Identity-based Attacks Are Breaching Retail 5 Ways Identity-based Attacks Are Breaching Retail The Hacker News
The New JavaScript Injection Playbook The New JavaScript Injection Playbook The Hacker News
Critical Wing FTP Server Vulnerability (CVE-2025-47812) Actively Being Exploited in the Wild Critical Wing FTP Server Vulnerability (CVE-2025-47812) Actively Being Exploited in the Wild The Hacker News
Chinese Hackers Exploit Linux Login Systems for Years Chinese Hackers Exploit Linux Login Systems for Years The Hacker News
Key Insights from the 2025 State of Pentesting Report Key Insights from the 2025 State of Pentesting Report The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GreatXML Exploit Circumvents Windows BitLocker Security
  • Anthropic Pauses AI Models Amid U.S. Export Controls
  • U.S. Halts Foreign Access to Anthropic’s AI Models
  • SHEETCREEP RAT Exploits Google Sheets for Covert Ops
  • CISA Urges Agencies to Address High-Risk Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GreatXML Exploit Circumvents Windows BitLocker Security
  • Anthropic Pauses AI Models Amid U.S. Export Controls
  • U.S. Halts Foreign Access to Anthropic’s AI Models
  • SHEETCREEP RAT Exploits Google Sheets for Covert Ops
  • CISA Urges Agencies to Address High-Risk Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark