惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
V2EX
S
SegmentFault 最新的问题
Apple Machine Learning Research
Apple Machine Learning Research
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
T
Tailwind CSS Blog
爱范儿
爱范儿
雷峰网
雷峰网
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - Franky
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
阮一峰的网络日志
阮一峰的网络日志
博客园 - 聂微东
Jina AI
Jina AI
V
Visual Studio Blog
博客园 - 【当耐特】
Last Week in AI
Last Week in AI
大猫的无限游戏
大猫的无限游戏
博客园_首页
The Cloudflare Blog
罗磊的独立博客
美团技术团队
P
Proofpoint News Feed
S
Securelist
K
Kaspersky official blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
NISL@THU
NISL@THU
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
The Hacker News
The Hacker News
C
Cisco Blogs
AWS News Blog
AWS News Blog
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
月光博客
月光博客
Simon Willison's Weblog
Simon Willison's Weblog
Project Zero
Project Zero
Cyberwarzone
Cyberwarzone
L
LINUX DO - 最新话题
C
CERT Recently Published Vulnerability Notes
Help Net Security
Help Net Security
T
Threat Research - Cisco Blogs
博客园 - 叶小钗
S
Secure Thoughts
有赞技术团队
有赞技术团队
博客园 - 司徒正美
宝玉的分享
宝玉的分享
Hacker News - Newest:
Hacker News - Newest: "LLM"
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO

GovInfoSecurity.com RSS Syndication

On Demand | Regulation Didn’t Change, Your Identity Landscape Did On Demand | Weaving Agentic AI into the SOC: A Practical Playbook for Operationalizing and Scaling Autonomy Why Periodic Pentesting Can’t Keep Up And What Security Leaders Are Doing Instead Claude Mythos 5 Can Build Exploits But Can't Power Campaigns AI Is Reshaping Cybersecurity Training Priorities Health Cyberthreat Sharing Is Advancing But Gaps Persist Are Small Models Closing the Gap on Frontier AI Cyber Tools? Government info security news, training, education Government info security news, training, education Government info security news, training, education Government info security news, training, education Beyond the Inbox: Defending Against AI-Enabled Social Engineering Webinar | 6 Layers Standing Between Your Enterprise and AI Risk Webinar | 6 Layers Standing Between Your Enterprise and AI Risk Webinar | Securing the Agentic Enterprise: An Integrated Policy Framework for Enterprise AI Security How AI Governance Protects Patient Care and Sensitive Data Why Hospitals Must Rethink Cyber Resilience The Privacy Risks of Embedded, Shadow AI in Healthcare Why Election Systems Are Now a Persistent Cyber Target Anthropic Submits Pre-IPO SEC Filing, Leads Market Cap Fight AI Agents Are the New Insiders Demystifying Claude: Signal vs. Speculation German Court: Google Liable for AI Summaries DOJ, FBI Seize 13 Domains in Chinese Recruitment Op A Security Gets $37M to Thwart Weaponized AI With Automation Breach Roundup: CISA Says Agencies Should 'Patch Smarter' Google Sues Chinese Phishing Service Over Gemini Abuse Policy as Code: From Documents to Machine Intelligence Anthropic Limits on OT Access to Mythos Draw Criticism Ozempic Drug Maker Loses Clinical Trial Data in Hack ISMG Editors: Anthropic Unleashes Claude Mythos 5 ISACA Survey: AI Adoption Is Rising, Visibility Is Not Webinar | Frontier AI and Identity Security in Financial Services US Pulls the Plug on Anthropic's Top AI Models US Anthropic Export Controls Sparks Sharp EU Reaction 1Password Buys Apono to Expand AI Access Governance Why Banks Must Align Stakeholders Before Scaling AI Geopolitics Is Now a Cybersecurity Problem Why AI Defenses Fail Without Data and Identity Fundamentals Labcorp Agrees to Pay $35M to Settle AMCA Data Breach NewCore Launches With $66M to Rebuild Identity for AI Agents GovSec Summit USA 2026: Cyber Resilience Amid Fiscal Reality How FDA Mythos Shutdown Contains a Message: Don How FDA
ShinyHunters Hits Universities Via Oracle Zero-Day
Chris Riotta · 2026-06-16 · via GovInfoSecurity.com RSS Syndication

Cybercrime , Fraud Management & Cybercrime

Mandiant: 68% of Targets Were Higher Ed Institutions Running PeopleSoft (@chrisriotta) • June 15, 2026    
ShinyHunters Hits Universities Via Oracle Zero-Day
Image: Jure Divich/Shutterstock

The hacking group ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft in an active extortion campaign impacting more than 100 organizations globally.

See Also: Why Cyberattackers Love 'Living Off the Land'

Researchers at Mandiant and Google's Threat Intelligence Group attributed the ongoing campaign to the financially motivated threat group in a blog post published Thursday. Researchers said they observed the activity between May 27 and June 9, and notified more than 100 organizations whose IP addresses matched with potentially vulnerable endpoints - with the majority of targets operating in the higher education sector.

Sixty-eight percent of the organizations Mandiant alerted were academic institutions, including universities and colleges worldwide. Several successfully blocked the activity or remediated the vulnerability, but some experienced compromise that resulted in stolen data being published on the ShinyHunters data leak site on June 9.

The campaign exploited a remote code execution vulnerability tracked as CVE-2026-35273, found within the environment management component of Oracle PeopleSoft. The flaw - which carries a CVSS score of 9.8 - allowed the attackers to achieve remote code execution without authentication, providing a direct path into the affected application infrastructure.

The vulnerability was used as a zero-day for the full duration of the campaign. Oracle published an advisory only after the activity began, according to the researchers - one day after stolen data from affected organizations first appeared on the ShinyHunters leak site.

ShinyHunters is a financially-motivated group with a history of large-scale data theft and extortion targeting organizations across a wide variety of sectors (see: Wave of ShinyHunters Extortion Drives Surge in Data Leaks).

Mandiant said the group deployed customized MeshCentral remote management agents disguised as authentic Microsoft Azure services to blend in with enterprise environments.

Researchers gained visibility into the full scope of attacker operations after a security researcher identified open directories on five sequential staging server IP addresses. The command history showed attackers used the MeshCentral tool to run administrative queries on compromised endpoints and identify additional application servers within victim networks.

ShinyHunters has focused its extortion operations on organizations that hold large volumes of potentially sensitive personal data, like schools and universities. The group previously leaked data stolen from Harvard and the University of Pennsylvania as part of earlier shakedown efforts targeting higher education (see: Harvard, UPenn Data Leaked in ShinyHunters Shakedown).

Mandiant urged organizations running Oracle PeopleSoft to immediately block external access to vulnerable endpoints and to audit WebLogic access logs for suspicious requests originating from external IP addresses. Researchers also recommended scanning the PSEMHUB web application directory for unexpected JSP files and reviewing filesystem paths for any unauthorized activity.