The ShinyHunters extortion crew exploited an unpatched remote code execution vulnerability in Oracle PeopleSoft (CVE-2026-35273) to breach enterprise systems, primarily targeting universities. The flaw, rated 9.8 critical, requires no authentication and allows full server takeover via HTTP. Mandiant (tracking the group as UNC6240) confirmed active exploitation between May 27 and June 9, 2026. Attackers used exposed staging servers with custom MeshCentral agents disguised as Azure binaries and lateral-movement scripts. Over 100 organizations were notified; 68% were higher education institutions in the US. The University of Nottingham is a confirmed victim, with 455,000 unique emails leaked. Oracle’s advisory recommends disabling the Environment Management Hub or blocking external access to specific endpoints. ShinyHunters has shifted from SaaS attacks to on-premises ERP exploitation, raising concerns about broader targeting.
CVEs: CVE-2026-35273, CVE-2026-11645
Attack groups: ShinyHunters, UNC6240
Companies: Oracle, Mandiant, TrendAI
Products: Oracle PeopleSoft, PeopleTools, MeshCentral, Microsoft Azure
Original source: thehackernews.com