Targets Education Sector with Oracle PeopleSoft Exploit

Reported 11 Jun 2026 by otx · Severity: medium

Between May 27 and June 9, 2026, UNC6240 (ShinyHunters) conducted an active compromise and extortion campaign targeting Oracle PeopleSoft application infrastructure. The threat actor exploited CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Enviro