DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:12:51ZSOURCES: 14CRITICAL: 31
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — Sampled credentials from the FortiBleed dataset and confirmed they are authentic. Many of… /// @MsftSecIntel CRITICAL — Tracking FortiBleed downstream activity. Buyers of the FortiGate credential sets are… /// @TalosSecurity CRITICAL — FortiBleed is just one piece of a broader IAB operation. The same Russian-speaking actor… /// @MalwareHunterTeam CRITICAL — The Gentlemen RaaS internal data leak (May 2026, ~16GB) confirmed operators actively… /// @CrowdStrike CRITICAL — Gentlemen RaaS affiliates are deploying GentleKiller variants that specifically target…
31Critical Threats
18Active CVEs
19IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-35273PUBLISHED: 2026-06-10
CRITICALCVE-2026-35273★ CISA KEV LISTED

Oracle PeopleSoft PeopleTools Unauthenticated RCE (ShinyHunters Zero-Day)

VENDOR: Oracle//PRODUCT: PeopleSoft Enterprise PeopleTools
9.8
CRITICAL
CVSS 3.1
PATCH STATUS
PARTIAL PATCH
EXPLOIT STATUS
LIMITED EXPLOITATION

A critical unauthenticated remote code execution vulnerability in the Updates Environment Management component (PSEMHUB) requires only HTTP network access with no user interaction. Mandiant (Google GTIG) confirmed active exploitation by ShinyHunters (UNC6240) as a zero-day between May 27 and June 9, 2026 — 14 days before Oracle's advisory — resulting in confirmed breaches at over 100 organizations, 68% in higher education, including the University of Nottingham (455,000 students' PII exfiltrated). ShinyHunters chained this with CVE-2026-35278 (CVSS 9.8) to achieve lateral movement, credential harvesting, and extortion.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONSPeopleSoft Enterprise PeopleTools 8.61 and 8.62 (earlier unsupported versions may also be affected)
  • https://www.oracle.com/security-alerts/alert-cve-2026-35273.html
  • https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit
  • https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html
  • https://www.helpnetsecurity.com/2026/06/11/oracle-peoplesoft-under-attack-cve-2026-35273/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn