Portsuppe

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

Mandiant Blog·11h·Reputable

Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component. The exploitation of this vulnerability directly aligns wit

Categories cybersecurity · government-security · unknown-it-category-15
Original source / advisory
Published
6/11/2026, 2:00:00 PM
Fetched
6/12/2026, 12:19:12 AM
Trust
reputable · 80/100
Language
en