CVE Tools

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

MandiantBy Mandiant9 min read

Reported exploitedOracle PeopleSoft Environment Management Hub (PSEMHUB)UNC6240 (ShinyHunters)
Read at Mandiant

Below is the opening; the full story is at Mandiant.

From Mandiant

Introduction

Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component. The exploitation of this vulnerability directly aligns with the observed targeting of Environment Management Hub (PSEMHUB) endpoints. Because this activity predates Oracle's June 10, 2026 advisory, the vulnerability was exploited as a zero-day.…

Continue at Mandiant

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store