FeedVulnerabilityGoogle warns of Oracle PeopleSoft attacks hitting universiti...
VulnerabilityCyber Insider
9.8CRITICAL

Google warns of Oracle PeopleSoft attacks hitting universities

📅 12 June 2026 at 16:38 UTC📰 Cyber InsiderView original source ↗
Google warns of Oracle PeopleSoft attacks hitting universities

Google's Mandiant and Google Threat Intelligence Group (GTIG) say the ShinyHunters extortion group exploited a critical Oracle PeopleSoft vulnerability as a zero-day to compromise education institutes. The activity, tracked as UNC6240, was observed between May 27 and June 9 and involved exploitation of CVE-2026-35273, a critical remote code execution flaw in the Environment Management component … The post Google warns of Oracle PeopleSoft attacks hitting universities appeared first on CyberInsider.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

The ShinyHunters extortion group exploited a critical Oracle PeopleSoft vulnerability (CVE-2026-35273) to compromise education institutes, specifically targeting PeopleSoft Environment Management Hub endpoints in the United States and higher education sector.

⚙️Technical Details
Affected Systems
Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62
💥Impact Assessment
Severity: Critical
🛡️Recommended Actions
1Disable the Environment Management Hub service where possible
2Block external access to PSEMHUB endpoints
3Review WebLogic access logs for suspicious requests
📦Affected Products
Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62
🔐NVD Verified DataVERIFIED
CVE-2026-35273CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-306

Read the full article

This is a curated summary. The complete article is available at Cyber Insider.

Read on Cyber Insider
← Back to feed