ShinyHunters Exploits Oracle PeopleSoft Zero-Day CVE-2026-35273 in Mass Hacking Campaign
Image: Zamin.uz

ShinyHunters Exploits Oracle PeopleSoft Zero-Day CVE-2026-35273 in Mass Hacking Campaign

10 June, 2026.Crime.25 sources

The story in 15 seconds

  • ShinyHunters exploited CVE-2026-35273 in Oracle PeopleSoft, breaching 100+ organizations, mostly universities.
  • Oracle issued an out-of-band advisory and patch for the unauthenticated RCE flaw.
  • ShinyHunters extorted victims, threatening data leaks after breaches across higher education.

The divide · 1 of 3

Whether Oracle has released a patch/fix

Conflicting reporting affects urgency and what defenses teams can apply.

Who skipped what

How each outlet frames it

Every outlet we compared, the headline it ran, and a link to the original article.

Source Diversity
25 sources
Other
17
Western Mainstream
5
Western Alternative
2
Local Western
1

Western Mainstream

Ars Technica
Ars Technica

PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data

12 June, 2026

Read the original →
TechCrunch
TechCrunch

Cybercriminals claim breach of Oracle PeopleSoft servers at 100-plus organizations

10 June, 2026

Read the original →
TechCrunch
TechCrunch

Oracle warns of security bug that hackers abused to breach 100+ companies

11 June, 2026

Read the original →
TechRadar
TechRadar

Oracle warns of critical PeopleSoft attack affecting hundreds of customers

12 June, 2026

Read the original →
The Hacker News
The Hacker News

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

11 June, 2026

Read the original →

Other

BleepingComputer
BleepingComputer

Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks

10 June, 2026

Read the original →
Computer Weekly
Computer Weekly

Oracle fixes PeopleSoft flaw exploited by ShinyHunters

12 June, 2026

Read the original →
CSO Online
CSO Online

Oracle PeopleSoft zero‑day fuels ShinyHunters extortion spree

12 June, 2026

Read the original →
CyberScoop
CyberScoop

ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw

12 June, 2026

Read the original →
Cybersecurity Dive
Cybersecurity Dive

ShinyHunters linked to exploitation of critical flaw in Oracle PeopleSoft

12 June, 2026

Read the original →
Dark Reading
Dark Reading

ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed

12 June, 2026

Read the original →
Hackread
Hackread

ShinyHunters Target Universities in Oracle PeopleSoft Zero-Day Attack

12 June, 2026

Read the original →
Help Net Security
Help Net Security

Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert

11 June, 2026

Read the original →
Oracle Blogs
Oracle Blogs

Security Alert CVE-2026-35273 Released

11 June, 2026

Read the original →
Rescana
Rescana

Oracle PeopleSoft PeopleTools Zero-Day (CVE-2026-35273) Actively Exploited: Urgent Patch Required to Prevent Ransomware and Data Breaches

11 June, 2026

Read the original →
Security Boulevard
Security Boulevard

Oracle PeopleSoft Servers Hacked in ShinyHunters Data Theft Attacks

11 June, 2026

Read the original →
SecurityWeek
SecurityWeek

Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks

11 June, 2026

Read the original →
SecurityWeek
SecurityWeek

Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters

12 June, 2026

Read the original →
Technology Org
Technology Org

ShinyHunters Hackers Exploit Unpatched Oracle Bug to Steal Data From 100+ Companies

12 June, 2026

Read the original →
Techzine Global
Techzine Global

ShinyHunters targets Oracle PeopleSoft

11 June, 2026

Read the original →
The Register
The Register

ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day

11 June, 2026

Read the original →
Zamin.uz
Zamin.uz

Hackers breach Oracle PeopleSoft servers of over 100 organizations

10 June, 2026

Read the original →

Western Alternative

Crypto Briefing
Crypto Briefing

Oracle PeopleSoft servers targeted in data theft attacks linked to ShinyHunters

10 June, 2026

Read the original →
The Tech Buzz
The Tech Buzz

ShinyHunters Claims Breach of 100+ Oracle PeopleSoft Servers

10 June, 2026

Read the original →

Local Western

mezha.net
mezha.net

ShinyHunters breached Oracle PeopleSoft at 100+ organizations, exposing student and staff data

10 June, 2026

Read the original →

Full story

Zero-day used on PeopleSoft

Mandiant CTO Charles Carmakal warned that the flaw is remotely exploitable without authentication and may result in remote code execution, affecting PeopleSoft PeopleTools versions 8.61 and 8.62.

Image from Ars Technica
Ars TechnicaArs Technica

Mandiant and the Google Threat Intelligence Group confirmed that ShinyHunters (UNC6240) targeted Oracle PeopleSoft application infrastructure between May 27, 2026 and June 9, 2026, and said the activity “is consistent” with exploitation of CVE-2026-35273.

Oracle’s advisory said the vulnerability is remotely exploitable without authentication and “may result in remote code execution,” while TechCrunch reported Oracle had not released a patch “at the time of writing.”

Higher education hit, data leaked

Mandiant said it notified more than “100 global organizations,” most of them in the United States, and TechCrunch reported that about two-thirds of those organizations are in higher education.

The campaign’s impact included stolen data being published on the ShinyHunters [Data Leak Website], and Mandiant wrote that “others experienced compromise, resulting in stolen data being published.”

Image from BleepingComputer
BleepingComputerBleepingComputer

The University of Nottingham confirmed it suffered a cybersecurity incident and that it notified affected students and alumni directly, while Cybersecurity Dive reported the university said a “significant amount of data” in its student records was compromised.

Cybersecurity Dive added that the flaw was added to CISA’s Known Exploited Vulnerabilities catalog and confirmed it has been used in ransomware attacks, and it said federal civilian agencies have until Monday to remediate the vulnerability.

Mitigations and ongoing extortion

Oracle urged customers to apply mitigations and take “immediate action” to reduce exposure, including disabling the Environment Management Hub service in Multi-Server configurations or removing the PSEM hub in Single-Server configurations.

If organizations could not disable the EMHub service, Oracle guidance described blocking external access to /PSEMHUB/* and /PSIGW/HttpListeningConnector at the network perimeter or firewall level, and Mandiant warned that WAF body-inspection rules alone are not enough.

Researchers tied to Mandiant and the Google Threat Intelligence Group said the attackers used customized MeshCentral agents disguised as Microsoft Azure services, and the campaign relied on remote code execution without authentication to take over exposed systems.

CyberScoop reported that Charles Carmakal said, “This campaign is still active,” and it described extortions being sent as recently as that Thursday evening, with the implication that more victims beyond Google’s visibility may be impacted.

The deep audit

How victims, perpetrators and terms are handled across outlets.

More on Crime