ShinyHunters exploits critical PeopleSoft zero-day vulnerability

A ransomware group known as ShinyHunters exploited a critical zero-day flaw in Oracle’s PeopleSoft software to target about 100 organizations. The attackers stole gigabytes of data from victims, including the University of Nottingham, and issued extortion demands. Oracle has released a mitigation but not a full patch.

ShinyHunters began exploiting the server-side request forgery vulnerability, tracked as CVE-2026-35273, on May 27. The flaw carries a severity rating of 9.8 out of 10 and remained unpatched for more than two weeks. Mandiant researchers reported that the group targeted roughly 300 endpoints across 100 organizations, with 68 percent in higher education.

The University of Nottingham confirmed on June 10 that a significant amount of student data had been stolen. ShinyHunters published the data on its leak site and demanded payment from at least one victim. Oracle issued an emergency security advisory and stopgap mitigation measures.

The attackers left behind scripts and a staging server that revealed reconnaissance activity and data compression using the zstd tool. One victim lost 48 gigabytes of information. Mandiant and Rapid7 have shared indicators of compromise to help affected organizations respond.

Labaran da ke da alaƙa

Illustration of Zcash price drop after Orchard vulnerability disclosure showing cracked shield and falling chart
Hoton da AI ya samar

Zcash price falls after Orchard bug disclosure

An Ruwaito ta hanyar AI Hoton da AI ya samar

Zcash token ZEC dropped sharply after developers disclosed a vulnerability in the Orchard shielded pool that could have allowed undetected counterfeiting of tokens. The flaw, present since 2022, was found on May 29 using an AI model and patched by June 1. No evidence of exploitation was found, though privacy features prevent cryptographic proof.

As the April 14 ransom deadline approaches, ShinyHunters has reiterated threats to release breached Rockstar Games data obtained via third-party Anodot, following the studio's confirmation of limited non-material access with no player impact. This updates coverage of the initial breach claim reported earlier this week.

An Ruwaito ta hanyar AI

A data breach at education technology provider Infinite Campus has exposed the personal information of more than 137,000 school staff members after threat actors compromised the company's Salesforce environment.

A group calling itself the Internet Yiff Machine has released 93 gigabytes of data purportedly stolen from P3 Global Intel, a platform used by Crime Stoppers programs and law enforcement for managing anonymous crime tips. The data, containing sensitive personal information on millions of tips, was sent to Straight Arrow News and the Distributed Denial of Secrets archive. Navigate360, which owns P3, has not confirmed the breach but hired a digital forensics firm to investigate.

An Ruwaito ta hanyar AI

Security engineer Taylor Hornby used an AI model to identify a critical vulnerability in the Zcash cryptocurrency that had remained undetected since 2022. The flaw could have permitted unlimited creation of counterfeit tokens. Hornby has now added Monero to his list of planned audits.

Wannan shafin yana amfani da cookies

Muna amfani da cookies don nazari don inganta shafin mu. Karanta manufar sirri mu don ƙarin bayani.
Ƙi