← Back to Feed

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

CVE-2026-35273

June 11, 2026 · Google Cloud Security · Severity: CRITICAL

Mandiant and Google Threat Intelligence Group identified a campaign by ShinyHunters exploiting CVE-2026-35273, a critical zero-day in Oracle PeopleSoft. The attackers targeted over 100 organizations, primarily in higher education, using MeshCentral agents to move laterally and steal data. The campaign led to data leaks on the ShinyHunters data leak site.

Key Takeaways

  • ShinyHunters exploited a zero-day in Oracle PeopleSoft to target education sector organizations.
  • Over 100 global organizations were notified, with 68% in higher education.
  • Attackers used customized MeshCentral agents for lateral movement and data exfiltration.
☕ Buy a Coffee