惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
Y
Y Combinator Blog
Engineering at Meta
Engineering at Meta
D
Docker
GbyAI
GbyAI
aimingoo的专栏
aimingoo的专栏
大猫的无限游戏
大猫的无限游戏
腾讯CDC
P
Proofpoint News Feed
A
About on SuperTechFans
WordPress大学
WordPress大学
Stack Overflow Blog
Stack Overflow Blog
Google DeepMind News
Google DeepMind News
C
Check Point Blog
Microsoft Security Blog
Microsoft Security Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
L
LangChain Blog
MyScale Blog
MyScale Blog
博客园 - 三生石上(FineUI控件)
Hugging Face - Blog
Hugging Face - Blog
Microsoft Azure Blog
Microsoft Azure Blog
N
Netflix TechBlog - Medium
G
Google Developers Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

Gadget Review

Bernie Sanders Wants You to Own Half of OpenAI - And He's Not Kidding - Gadget Review California Bill Strikes Back Against Disappearing Video Games - Gadget Review Japan Cracks 6G's Speed Barrier With 112 Gbps Wireless Breakthrough - Gadget Review 31 Amazon Kitchen Tools and Gadgets That Make Prep Time a Breeze The 559-Mile Mic-Drop: Why BMW’s New i3 Just Made Tesla’s Range Look Like A Toy - Gadget Review 20 Genius Camping Gadgets That Will Help Make Summer Camping Easier Tesla Patents Transform Glass Roofs Into Smart Air Conditioners - Gadget Review Is Anthropic’s “Benefit Corp” Structure An Investor’s Worst Nightmare? - Gadget Review How An AI Weather Startup Just Beat the World’s Greatest Supercomputers - Gadget Review Dell's New XPS 13 Is Directly Targeting The MacBook Neo - Gadget Review 13 Smart Home Gadgets for True Local Control (No Cloud Needed!) Florida Sues OpenAI and CEO Sam Altman - Why Florida Is Treating AI Chatbots as "Hazardous Products" - Gadget Review Malaysia’s Scorched-Earth Policy Against Under-16 Social Media Access - Ban Carries Fines Up To $2.5 Million - Gadget Review PlayStation's Wireless Fight Stick and Latest Gaming Monitor Hits This August - Gadget Review How Meta's Chatbot Handed Over Million-Dollar Instagram Accounts To Attackers - Gadget Review 11 Home Security Gadgets That Help Safeguard Your Sanctuary Engineer Builds AI-Powered Laser System That Targets & Hunts Mosquitoes at Home - Gadget Review DuckDuckGo's No-AI Search Extensions Surge as Users Flee Google's AI Overhaul - Gadget Review Google Wants to Release 32 Million "Infected" Mosquitoes Into The Wild - Gadget Review Nvidia Is Bringing AI Power To Your Desk With New Superchip - Gadget Review Tech CEOs Are Using AI as the Perfect Scapegoat for Mass Layoffs - Gadget Review Wix Cuts 1,000 Jobs, Citing AI Evolution and Currency Pressures - Gadget Review Teen's Bluetooth Speaker Named "BOMB" Forces Flight U-Turn Mid-Atlantic - Gadget Review China's Humanoid Robots Sort 1,200 Postal Packages Per Hour - Gadget Review California Senate Passes Historic Ban on AI Chatbot Toys - Gadget Review Professor Declares War on AI: Will Fail Any Student Who Uses It - Gadget Review UK Military Looks At Allowing Lethal Strikes With Zero Human Intervention - Gadget Review Chinese EVs Are Tanking in Value - Gadget Review Japanese Researchers Create Chip That Could Run 1,000x Faster, Near-Zero Heat - Gadget Review Total Immobility: Why A Single Targeted Cyberattack Could Leave Every EV In Your City Stranded - Gadget Review
Oracle PeopleSoft Zero-Day Exposes 100+ Companies - Gadge...
Nikshep Myle · 2026-06-13 · via Gadget Review

ShinyHunters exploited CVSS 9.8 vulnerability in PeopleTools 8.61 and 8.62 to steal student records from universities

The ShinyHunters cybercrime group weaponized CVE-2026-35273 to breach PeopleSoft servers across mostly U.S. organizations, with roughly two-thirds targeting universities according to Google-owned incident response firm Mandiant. Your institution’s HR systems and student records—grades, demographics, contact details, even GPAs—became prime extortion material while Oracle scrambled to issue emergency guidance. The vulnerability affects PeopleSoft PeopleTools versions 8.61 and 8.62, requiring no authentication for remote exploitation.

Critical Flaw Requires Zero Authentication

Attackers need nothing more than internet access to compromise vulnerable PeopleSoft servers.

The vulnerability earned Oracle’s highest threat rating: CVSS 9.8 critical. Remote code execution without authentication means attackers can compromise PeopleSoft PeopleTools from anywhere on the internet. Oracle’s security alert uses language reserved for the most severe exposures, calling mitigation implementation “a high-priority risk reduction measure” and strongly recommending “immediate action.” Your PeopleSoft deployment remains exposed until you apply their workarounds, which Oracle has detailed behind their customer support portal.

Universities Bear Brunt of Student Data Theft

Mandiant confirms higher education represents the majority of breach victims in this campaign.

Mandiant has notified affected organizations while coordinating damage assessment across the compromised systems. ShinyHunters claimed to steal “hundreds of thousands of student records” from at least one university, including full names, addresses, enrollment status, majors, and academic performance data. The group follows a consistent playbook: publish stolen data on leak sites when ransom demands go unpaid. According to Mandiant, “while several organizations successfully blocked the activity or remediated the vulnerabilities, others experienced compromise, resulting in stolen data being published.”

Pattern Emerges in Enterprise Software Targeting

ShinyHunters systematically exploits shared platforms for maximum victim impact across sectors.

This marks ShinyHunters’ latest campaign targeting organizations through common software vulnerabilities. Over the past year, the group exploited flaws in:

  • Salesforce
  • Gainsight
  • Instructure’s Canvas platform

The strategy mirrors other major breaches: find zero-days in widely deployed enterprise software, then harvest data from dozens of organizations simultaneously.

Oracle’s mitigation guidance emphasizes immediate action while patches remain unavailable. The company’s history suggests network segmentation, access restrictions, and disabling non-essential PeopleTools features provide temporary protection. Back-office systems you never think about hold your most sensitive institutional data, and hackers have figured out exactly where to strike.