ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit
CISA KEV means this flaw has been seen exploited in real attacks — not predicted, observed. Treat it as urgent regardless of its score.
- On CISA KEV — actively exploited. Patch immediately.
Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273 , a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component. The exploitation of this vulnerability directly aligns with the observed targeting of Environment Management Hub (PSEMHUB) endpoints. …
- CVE-2026-35273nvd ↗KEVEPSS 9%
- CVE-2026-0265nvd ↗EPSS 1%
- CVE-2026-50751nvd ↗KEVEPSS 6%
- CVE-2026-10520nvd ↗KEVEPSS 100%
- CVE-2026-10523nvd ↗EPSS 53%
- CVE-2026-41940nvd ↗KEVEPSS 99%
- CVE-2026-33032nvd ↗EPSS 3%
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.