<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

ShinyHunters Exploited Oracle Zero-Day to Hit Over 100 Organizations, Mostly Universities

ShinyHunters exploited a zero-day in Oracle PeopleSoft, affecting 100+ organizations. University of Nottingham breach reported, 40 GB data stolen.
Content Team

The ShinyHunters extortion gang exploited a critical zero-day vulnerability in Oracle's PeopleSoft software between May 27 and June 9, 2026, compromising more than 300 instances. The flaw, CVE-2026-35273 (CVSS 9.8), allowed unauthenticated remote code execution through PeopleSoft's Environment Management Hub service.

Mandiant and Google Threat Intelligence Group spotted the campaign and contacted more than 100 at-risk organisations, about 68% of them higher education institutions and most in the US. The University of Nottingham confirmed a breach, with ShinyHunters claiming more than 40 GB of sensitive data taken from its student records.

Oracle pushed an out-of-band patch on June 10, the day after being alerted. Organisations should disable the EMHub service or block external access to it immediately — researchers note doing so doesn't break PeopleSoft's core functionality.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo