READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

ShinyHunters Exploited a 9.8-Severity Oracle PeopleSoft Zero-Day for Two Weeks Before Oracle Warned Anyone

ShinyHunters Exploited a 9.8-Severity Oracle PeopleSoft Zero-Day for Two Weeks Before Oracle Warned Anyone
A critical, no-login-required remote code execution flaw in Oracle PeopleSoft was under active exploitation from May 27 through June 9, 2026. Oracle did not publish its advisory until June 10, leaving every affected institution in the dark for the entire attack window. Universities bore the brunt: 68% of the more than 100 organizations Google's threat team flagged were in higher education.

What Happened

The ShinyHunters extortion group exploited CVE-2026-35273, a remote code execution vulnerability in Oracle PeopleSoft's Environment Management component, rated 9.8 out of 10 on the CVSS severity scale. No login. No user interaction. Just network access over HTTP, and the server is theirs.

The active exploitation window ran from May 27 to June 9, 2026, according to Google Cloud's threat intelligence team (GTIG), which tracks the group as UNC6240. Oracle published its advisory on June 10 — one day after the attackers had already posted stolen data to ShinyHunters' public leak site. By every measurable definition, this was a zero-day the entire time it was being weaponized.

How the Attack Worked

The flaw sits in PeopleSoft's Updates Environment Management component, the infrastructure behind the Environment Management Hub (PSEMHUB). Oracle confirms PeopleTools versions 8.61 and 8.62 are affected and acknowledges that older, unsupported versions are likely vulnerable too.

Mandiant CTO Charles Carmakal confirmed exploitation in the wild. Oracle's own advisory, by contrast, included no indication of active exploitation. A discrepancy CSO Online flagged in its June 12 reporting. Oracle did not respond to CSO's request for comment.

The attackers' operational security failed them in a specific, traceable way. Researcher @nahamike01 publicly identified open directories the group had left exposed. Mandiant then triaged five sequential IP addresses running Python's SimpleHTTP server on port 8888. Those servers had left their staging files sitting in the open: a shared `.bash_history` file, custom MeshCentral remote-management agents disguised as Microsoft Azure binaries, and a lateral-movement script.

The agents phoned home to a command-and-control server at azurenetfiles.net — a domain engineered to look like Azure NetApp Files. The lateral-movement script, named after individual victims in the format `[victim]_fanout.sh`, spread through internal networks over SSH by spraying hardcoded username and password combinations against hosts pulled directly from `/etc/hosts`. It then dropped a file named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT into PeopleSoft directories.

Command history on the exposed servers showed data compressed with `zstd` and exfiltrated over an outbound SSH connection to the server hosting the public mirror of the ShinyHunters leak site, according to The Hacker News.

The Victims

GTIG notified more than 100 organizations whose internet-facing systems appeared potentially exposed. Sixty-eight percent were in higher education, most of them in the United States. Some organizations blocked the activity or patched in time. Others were compromised and had data published.

The University of Nottingham is among the confirmed victims. The ShinyHunters post on June 9 claimed the stolen trove included "over 40 GB of billing and payment records, credit card and payment details, student finance data, and campus portal exports," according to CSO Online. On June 11, the attackers posted a follow-up threatening to publish data if contacted victims missed their deadline.

The Patch Situation

Oracle's advisory points to a patch availability document locked behind a support login. Whether a complete, broadly deployable fix is available as of June 12 is unclear from public documentation. Current guidance centers on mitigation: any organization running PeopleSoft with the Environment Management Hub reachable from outside the network should restrict those endpoints immediately.

The Strongest Counterargument

A fair reading of Oracle's position: large enterprise software vendors often coordinate disclosure carefully to avoid tipping off additional attackers before patches reach customers. Publishing a zero-day advisory before a fix is fully available can, in some cases, expand the attack surface by broadcasting exactly where to look. Oracle credits Trend Micro Zero Day Initiative for reporting the flaw, which suggests it was working through a structured disclosure process. That process has genuine value.

The problem here is timing. Google's GTIG documented active exploitation beginning May 27. Oracle's advisory landed June 10. Whether Oracle knew about the exploitation before June 10 and chose to hold its advisory, or was itself unaware, is a question neither Oracle nor the public record has answered. That distinction matters enormously for how this disclosure should be judged.

What This Exposes Beyond the Patch

James Davison, chief strategy officer at Pathlock, told CSO Online that "the Oracle PeopleSoft breach is an example of the new kind of attacks every ERP will face in today's new agentic world," arguing that organizations need to fundamentally reassess their ERP security posture.

Davison works for a vendor adjacent to the ERP security market, making his case for ERP security spending an interested perspective worth labeling as such. The underlying technical point, however, stands. A 9.8-severity unauthenticated RCE bug that needs nothing more than HTTP access to execute is not a subtle threat. Universities, which frequently run internet-facing PeopleSoft portals for student enrollment and financial aid, are structurally exposed in ways that many private-sector organizations are not.

The unresolved question as of June 12: Oracle has not publicly confirmed whether a complete patch is available for download without a support contract, which means institutions that lack active Oracle support agreements may have no clear path to a fix beyond network-level mitigation.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
Ars TechnicaPeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data
unknown
thehackernewsShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities - The Hacker News
unknown
csoonlineOracle PeopleSoft zero‑day fuels ShinyHunters extortion spree | CSO Online
unknown
securityweekGoogle Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters