Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters

    June 14, 2026

    Is Echostar a Way to Get SpaceX at $80-113 Per Share ?

    June 14, 2026

    Weekly poll: what do you think about iOS 27?

    June 14, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters
    Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters
    Cybersecurity

    Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters

    The Tech GuyBy The Tech GuyJune 14, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Google has confirmed that a PeopleSoft vulnerability mitigated by Oracle this week has been exploited by ShinyHunters as a zero-day to steal data from organizations.

    Advertisement

    Oracle has released an out-of-band advisory and security alert for CVE-2026-35273, a critical unauthenticated remote code execution vulnerability impacting PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62, as well as PeopleSoft Enterprise Applications. 

    The software giant has released mitigations, but patches do not appear to be available.

    PeopleSoft is an ERP software suite used by many large organizations to manage a wide range of business functions, including HR, payroll, finance, supply chain, and campus operations. 

    While the solution is used across many industries, the ShinyHunters campaign exploiting CVE-2026-35273 appears to have focused on the education sector. The University of Nottingham in the UK is the first confirmed victim. 

    Mandiant and Google Threat Intelligence Group (GTIG) reported observing activity associated with the exploitation of the PeopleSoft zero-day between May 27 and June 9. The attacks have been attributed to ShinyHunters, which Google tracks as UNC6240.

    Advertisement. Scroll to continue reading.

    Google’s researchers notified more than 100 global organizations of potential exposure, the majority of which are based in the US, with 68% in the higher education sector. 

    The tech giant said some of the targets blocked the attack, but others had their systems compromised and data stolen.

    ShinyHunters claims to have targeted roughly 300 PeopleSoft instances belonging to 100 organizations.

    “The attacker staging environments hosted customized MeshCentral agents masquerading as legitimate cloud endpoints, which they used to run administrative command queries and deploy a custom lateral movement and defacement script, [victim_abbreviation]_fanout.sh,” Mandiant and GTIG explained. “This campaign directly correlates with subsequent data leaks of stolen organization data published on the ShinyHunters Data Leak Site (DLS) on June 9, 2026.”

    Google has shared remediation and hardening recommendations, as well as technical details on the attacks and indicators of compromise (IoCs).

    Oracle has not responded to SecurityWeek’s inquiry regarding exploitation. 

    TrendAI (Trend Micro’s enterprise business), whose researchers have been credited by Oracle for reporting CVE-2026-35273, told SecurityWeek that it’s currently seeing limited exploitation of the vulnerability, but its investigation is ongoing.

    Related: CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk

    Related: Hackers Exploit Langflow Vulnerability for Remote Code Execution

    Related: ‘GreatXML’ Zero-Day Exploit Bypasses BitLocker

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Anthropic Disputes Fable 5 AI Jailbreak

    June 14, 2026

    Chrome 149 Update Patches 28 Vulnerabilities

    June 13, 2026

    NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks

    June 13, 2026

    Anthropic Says It Has Taken Its Latest AI Models Offline to Comply With New Export Controls

    June 13, 2026

    Iranian Cyber Group Handala Claims Cal Water Hack

    June 13, 2026

    Industry Reactions to Claude Fable 5: Feedback Friday

    June 12, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 202672 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 202618 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters

    June 14, 2026

    Is Echostar a Way to Get SpaceX at $80-113 Per Share ?

    June 14, 2026

    Weekly poll: what do you think about iOS 27?

    June 14, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.