BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

ShinyHunters Exploit Oracle Zero-Day, Hit Universities

ShinyHunters exploit Oracle zero-day flaw, targeting universities to steal data

  • The ShinyHunters cybercrime group exploited a critical zero-day flaw in Oracle PeopleSoft to steal data from enterprise systems.
  • The vulnerability, CVE-2026-35273, allows unauthenticated remote code execution and was actively exploited before a patch was available.
  • Higher education institutions were the primary targets, with Google’s Mandiant notifying over 100 organizations, 68% of which were universities.
  • Attackers used a custom script to move laterally across networks and exfiltrate data, which was subsequently posted to a public leak site.

The ShinyHunters extortion crew launched a campaign in late May 2026, exploiting an unpatched flaw in Oracle PeopleSoft to breach enterprise systems and steal sensitive data. They primarily targeted universities, demanding payment to keep the stolen information private according to reports.

- Advertisement -

The critical vulnerability, tracked as CVE-2026-35273, allowed remote code execution without any login credentials. Consequently, attackers could take over servers simply by having network access over HTTP.

Mandiant CTO Charles Carmakal confirmed the bug was being exploited in the wild. Meanwhile, attackers left their own infrastructure exposed, which researchers publicly flagged.

Operational details revealed custom remote-management agents and a lateral-movement script designed to spread across internal networks. This script then compressed stolen data and connected to the attackers’ leak site.

The University of Nottingham has been confirmed as a victim, with data covering approximately 455,000 individuals leaked online. However, ShinyHunters claims more victim announcements are forthcoming.

- Advertisement -

Oracle’s immediate guidance was to disable the vulnerable Environment Management Hub service or block external access to specific endpoints. Organizations are urged to hunt for signs of compromise, such as unexpected files or unusual outbound traffic.

This attack marks a significant escalation for ShinyHunters, which has typically relied on social engineering. Exploiting a server-side zero-day in on-premises ERP software represents a more sophisticated approach.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

OpenAI Mulls AI Price Cuts Amid IPO Race, Tokenmaxxing Boom

OpenAI is contemplating significant price cuts for its AI tokens in anticipation of a...

NIO’s Onvo L60 SUV priced from $26,700, undercuts Tesla

The new Onvo L60 starts at RMB 192,800 ($26,600), undercutting the Tesla Model Y's...

GameStop pledges $300M Bitcoin to Coinbase

GameStop has pledged its entire 4,709 BTC treasury, worth roughly $300 million, to Coinbase...

Traders Bet Big on ETH Despite 44% Price Drop

Ether futures open interest on Binance has reached a new all-time high of 3.7...

GreatXML Bypass Exposes Windows BitLocker Security

A new Windows BitLocker encryption bypass tool named GreatXML has been released by security...

Must Read

Forex Trading Vs Crypto Trading: Which One Should You Choose?

So you're trying to decide between two types of trading: Forex and cryptocurrency.Forex trading is the big player in the trading world, with lots...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading