CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 308

As cited

Copy frozen at (site build).

vulnerabilities

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

Mandiant and Google Threat Intelligence identified UNC6240 (ShinyHunters) exploiting CVE-2026-35273, a critical remote code execution vulnerability in Oracle PeopleSoft's Environment Management component, between late May and early June 2026. The campaign primarily targeted higher education institutions in the United States, with attackers using custom MeshCentral agents for lateral movement and subsequently publishing stolen data on ShinyHunters' leak site. The exploitation occurred before Oracle's patch advisory, making it a zero-day attack that affected over 100 organizations.

Why it matters: Organizations running Oracle PeopleSoft should immediately assess exposure to CVE-2026-35273 (CVSS 9.8) and implement access controls on Environment Management Hub endpoints to prevent active exploitation and data theft.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

Mandiant and Google Threat Intelligence identified UNC6240 (ShinyHunters) exploiting CVE-2026-35273, a critical remote code execution vulnerability in Oracle PeopleSoft's Environment Management component, between late May and early June 2026. The campaign primarily targeted higher education institutions in the United States, with attackers using custom MeshCentral agents for lateral movement and subsequently publishing stolen data on ShinyHunters' leak site. The exploitation occurred before Oracle's patch advisory, making it a zero-day attack that affected over 100 organizations.

Why it matters: Organizations running Oracle PeopleSoft should immediately assess exposure to CVE-2026-35273 (CVSS 9.8) and implement access controls on Environment Management Hub endpoints to prevent active exploitation and data theft.

VendorsMicrosoftAppleGoogleOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary