Last updated 1 month ago
ShinyHunters is actively extorting universities after exploiting an unpatched Oracle PeopleSoft zero-day vulnerability. The attacks have been ongoing since late May 2026, targeting higher education institutions. Oracle has not yet released a patch for the flaw, leaving affected universities exposed to data theft and extortion demands.
The threat actor, ShinyHunters, is exploiting an unpatched Oracle PeopleSoft vulnerability to gain unauthorized access to university systems. The group has been using this zero-day since late May 2026, exfiltrating data and subsequently extorting the affected institutions. The specific CVE identifier for the vulnerability has not been disclosed, but the attack vector is exploitation of an unpatched flaw in Oracle's PeopleSoft product.
As of the article's publication on June 17, 2026, Oracle has not patched the vulnerability. The affected universities are facing extortion demands from ShinyHunters, who threaten to release stolen data if ransoms are not paid. No further details on containment, remediation, or regulatory involvement have been reported.
Exploitation of unpatched Oracle PeopleSoft zero-day vulnerability
Mandiant attributes the attacks to UNC6240 and identifies the exploited vulnerability as CVE-2026-35273, an unpatched Oracle PeopleSoft zero-day, with activity dated between May 27 and June 9, 2026.
This breach underscores the critical importance of timely patch management, especially for widely deployed enterprise software like Oracle PeopleSoft. The extended window of exploitation (since late May without a patch) highlights the need for organizations to implement compensating controls, such as web application firewalls and intrusion detection systems, when vendor patches are delayed. Additionally, universities should prioritize vulnerability disclosure programs and maintain offline backups to mitigate extortion risks.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor
MITRE ATT&CK