ShinyHunters Exploits Oracle PeopleSoft Zero‑Day (CVE‑2026‑35273) to Compromise 100+ Universities
What Happened — ShinyHunters (UNC6240) leveraged a critical, unauthenticated remote‑code‑execution flaw in Oracle PeopleSoft’s Environment Management component (CVE‑2026‑35273, CVSS 9.8) to infiltrate more than 100 organizations, 68 % of which were U.S. universities, before Oracle released an advisory. The campaign ran from 27 May to 9 June 2026, effectively a zero‑day attack.
Why It Matters for TPRM —
- Critical PeopleSoft vulnerability can affect any third‑party ERP/HR system used by education institutions and other enterprises.
- Exploitation occurred before a patch existed, highlighting the risk of undisclosed zero‑days in vendor products.
- The extortion‑focused campaign demonstrates that a compromised vendor can become a conduit for data theft and ransomware‑style pressure on downstream customers.
Who Is Affected — Higher‑education institutions, research labs, and any organization running Oracle PeopleSoft (PeopleTools 8.61/8.62 or earlier).
Recommended Actions —
- Verify whether your organization uses Oracle PeopleSoft; if so, confirm version and apply the June 10 2026 patch immediately.
- Review third‑party risk contracts for clauses on zero‑day exposure and vendor patch timelines.
- Conduct network segmentation and restrict access to the Environment Management Hub endpoint.
- Monitor for Indicators of Compromise (IoCs) published by Mandiant and Google Threat Intelligence.
Technical Notes — The flaw is a remote code execution vulnerability in the Environment Management Hub (PSEMHUB) that requires only network connectivity—no authentication or user interaction. Exploited binaries were disguised as Azure services and delivered via a staging infrastructure exposing .bash_history files. CVE‑2026‑35273 scores 9.8/10 (CVSS). Source: SecurityAffairs