Live Cybersecurity News Ticker | Codekeeper

ShinyHunters Exploited Oracle Zero-Day to Hit Over 100 Organizations, Mostly Universities

Written by Content Team | Jun 13, 2026, 12:22:12 PM

The ShinyHunters extortion gang exploited a critical zero-day vulnerability in Oracle's PeopleSoft software between May 27 and June 9, 2026, compromising more than 300 instances. The flaw, CVE-2026-35273 (CVSS 9.8), allowed unauthenticated remote code execution through PeopleSoft's Environment Management Hub service.

Mandiant and Google Threat Intelligence Group spotted the campaign and contacted more than 100 at-risk organisations, about 68% of them higher education institutions and most in the US. The University of Nottingham confirmed a breach, with ShinyHunters claiming more than 40 GB of sensitive data taken from its student records.

Oracle pushed an out-of-band patch on June 10, the day after being alerted. Organisations should disable the EMHub service or block external access to it immediately — researchers note doing so doesn't break PeopleSoft's core functionality.

Source: Dark Reading