discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Oracle mitigates PeopleSoft zero-day exploited in data theft attacks

Oracle has mitigated a critical PeopleSoft zero-day, CVE-2026-35273, after attackers used it in data theft campaigns. A patch is coming soon.

By Lawrence Abrams·Jun 11·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
Image: bleepingcomputer.com

Oracle says a critical PeopleSoft PeopleTools flaw, CVE-2026-35273, can allow unauthenticated remote code execution. BleepingComputer and Mandiant tied it to ShinyHunters-style data theft attacks, with more than 100 organizations notified.

Why it matters

This is a high-severity enterprise zero-day with confirmed real-world exploitation, not a theoretical bug. The reporting suggests broad impact, especially for education and other organizations running PeopleSoft, and shows attackers can use one weakness to steal data at scale.

A locked door in a school office system had a hidden weakness, and burglars found it before the lock maker could fully fix it. Oracle has put up emergency barriers, but teams still need to check for footprints and broken windows.

Analysis

What Oracle confirmed

Oracle says CVE-2026-35273 affects PeopleSoft PeopleTools versions 8.61 and 8.62. The company describes it as remotely exploitable without authentication and capable of remote code execution, which is why the flaw carries a CVSS score of 9.8. Oracle has released emergency mitigations and says a full patch is coming soon.

How attackers used it

BleepingComputer reports that the bug was the zero-day used in data theft attacks linked to ShinyHunters. The article says the group claimed it used a "gadget chain" of old and zero-day flaws to break into PeopleSoft instances and steal data from 300 instances across more than 100 organizations. Mandiant later confirmed that threat actors were exploiting the Oracle PeopleSoft flaw as a zero-day and said most of the organizations it notified were based in the United States, with 68% in higher education.

What the defenders saw

According to Mandiant, the attackers did more than simple intrusion. They used customized MeshCentral remote management agents disguised as Microsoft Azure services, staged tools on their infrastructure, and moved through compromised networks by mapping PeopleSoft and WebLogic configurations. The researchers also said the attackers used scripts for lateral movement.

What security teams should do

Mandiant advised organizations to restrict access to sensitive PeopleSoft endpoints tied to the exploit chain, review logs for suspicious requests to /PSEMHUB/ and /PSIGW/HttpListeningConnector, and look for webshells, unauthorized files, and other signs of compromise. The article also notes that BleepingComputer reached out to Oracle for comment but had not received a response at publication time.

Key points

  • Oracle says CVE-2026-35273 is a critical PeopleSoft PeopleTools zero-day that can enable unauthenticated remote code execution.
  • BleepingComputer reports the flaw was actively used in ShinyHunters-linked data theft attacks.
  • Mandiant said it notified more than 100 global organizations, most of them in the United States and many in higher education.
  • Attackers reportedly used customized MeshCentral agents and mapped PeopleSoft and WebLogic setups inside compromised networks.
  • Oracle has issued emergency mitigations and says a patch is coming soon.
The Upside

Oracle has already shipped emergency mitigations, which can reduce exposure before the full patch arrives. Mandiant also shared concrete hunting guidance, giving defenders a clearer path to spot suspicious activity and contain damage.

The Downside

If organizations delay mitigation, attackers may keep using the flaw to steal data or move deeper into internal systems. The article suggests the campaign already reached many organizations, so any unpatched PeopleSoft instance may remain a live target until the final fix is deployed.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritytechglobal-newsunited-states

Author

Lawrence Abrams

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 11, 2026

Source

bleepingcomputer.com

Share

Topics

securitytechglobal-newsunited-states

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…