← Back to Feed

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

CVE-2026-35273

June 11, 2026 · Google Cloud Security · Severity: CRITICAL

Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure.

Key Takeaways

  • Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion.
  • The attacker staging environments hosted customized MeshCentral agents masquerading as legitimate cloud endpoints. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of.
☕ Buy a Coffee