Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageVulnerabilities Desk
Vulnerabilities

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

University targeting suggests the group prioritizes high-value research data and academic credentials over traditional financial targets.

Summary written by editorial AI · Source link below

Filed by THN (Feedburner)1 min readCVE-2026-35273Read at source ↗
CVSS9.8criticalCVE-2026-35273

The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest.

Google's Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9. Oracle did not publish its advisory until June 10, so the bug was a

Editorial Analysis

Why it matters

The focus on educational institutions indicates threat actors are increasingly targeting intellectual property and research data as valuable commodities.

What to do

Prioritize patching for enterprise software used in research and development environments.

Board brief

Cybercriminals are increasingly targeting universities and research institutions for intellectual property theft.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at THN (Feedburner)

External link — opens at THN (Feedburner) in a new tab.

§
Continue with

More from the Vulnerabilities Desk