{"id":270638,"date":"2026-06-11T16:29:00","date_gmt":"2026-06-11T20:29:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/06\/11\/shinyhunters-exploits-oracle-peoplesoft-zero-day-cve-2026-35273-to-breach-universities\/"},"modified":"2026-06-11T17:15:22","modified_gmt":"2026-06-11T21:15:22","slug":"shinyhunters-exploits-oracle-peoplesoft-zero-day-cve-2026-35273-to-breach-universities","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/06\/11\/shinyhunters-exploits-oracle-peoplesoft-zero-day-cve-2026-35273-to-breach-universities\/","title":{"rendered":"ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/06\/shinyhunters-exploits-oracle-peoplesoft.html\">ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/06\/shinyhunters-exploits-oracle-peoplesoft.html\">https:\/\/thehackernews.com\/2026\/06\/shinyhunters-exploits-oracle-peoplesoft.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-06-11 16:29:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Swati Khandelwal<\/span>\ue802<span class=\"author\">Jun 11, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Data Breach<\/span><\/p>\n<p>The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest.<\/p>\n<p>Google&#8217;s Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9. Oracle did not publish its advisory until June 10, so the bug was a zero-day the entire time.<\/p>\n<p>The flaw, CVE-2026-35273, is a remote code execution bug in PeopleSoft Enterprise PeopleTools rated 9.8 out of 10. It needs no login and no user interaction, just network access over HTTP, to take over the server. If you run PeopleSoft with the Environment Management Hub reachable from outside, that is your exposure, and the immediate move is to lock those endpoints down.<\/p>\n<p>The vulnerability sits in the Updates Environment Management component, the piece behind the Environment Management Hub (PSEMHUB). Oracle lists PeopleTools 8.61 and 8.62 as affected and says earlier, unsupported versions are probably vulnerable too. It credits researchers from TrendAI Zero Day Initiative and TrendAI Research for the report.<\/p>\n<p>Mandiant CTO Charles Carmakal confirmed the bug is being exploited in the wild; Oracle has not said whether it has seen exploitation. Its advisory points to a patch availability document behind a support login, and whether a full fix is broadly available is unclear. For now, the guidance centers on mitigation.<\/p>\n<p><img decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/p>\n<p>The operational detail became public because the attackers left their own gear exposed. Researcher @nahamike01 publicly flagged the open directories. Mandiant then triaged five sequential IP addresses running Python&#8217;s SimpleHTTP server on port 8888. Those servers exposed the staging files: a shared .bash_history, custom MeshCentral remote-management agents disguised as Microsoft Azure binaries, and a lateral-movement script.<\/p>\n<p>The agents called home to a command-and-control&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/06\/shinyhunters-exploits-oracle-peoplesoft.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities https:\/\/thehackernews.com\/2026\/06\/shinyhunters-exploits-oracle-peoplesoft.html Publish Date: 2026-06-11 16:29:00 Source&#8230;<\/p>\n","protected":false},"author":1,"featured_media":270639,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgBpNcbfulhruio1VSh8OPKOjdx3gvP-Chg8OjSm7LZeVK2GaVR-osKeoQjO9e1_56Dtedmlisu76lYc70Wv5I1efqJcs2uh1RnbKJOITEcqcJoN-8PhNfmzAeLkDrST8Kg3qTbqE8wUrOd4jxE-gMi-vKN1B8W2zgY0ymFTtip79RVltY9J3QmXrAOJa4H\/s1700-e365\/shinyHunters-universities.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[30,90,89,27],"class_list":["post-270638","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-breach","tag-cve","tag-flaw","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/270638"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=270638"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/270638\/revisions"}],"predecessor-version":[{"id":270640,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/270638\/revisions\/270640"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/270639"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=270638"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=270638"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=270638"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}