Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CSS Bomb Attacks Steal Passwords via Malicious Emails
August 9, 2026
Levi Strauss Data Breach Exposes Customer and Employee Data
August 8, 2026
OpenAI Pauses Astra Model Development to Assess Cybersecurity Risks
August 8, 2026
Home/CyberSecurity News/Critical Oracle PeopleSoft CVE-2024-XXXX RCE Zero-Day Exploited by ShinyHunters
CyberSecurity News

Critical Oracle PeopleSoft CVE-2024-XXXX RCE Zero-Day Exploited by ShinyHunters

Key Takeaways A critical zero-day vulnerability in Oracle PeopleSoft, CVE-2026-35273, was actively exploited by the ShinyHunters group (also known as UNC6240). The unauthenticated remote code...

David kimber
David kimber
June 12, 2026 3 Min Read
50 0

Key Takeaways

  • A critical zero-day vulnerability in Oracle PeopleSoft, CVE-2026-35273, was actively exploited by the ShinyHunters group (also known as UNC6240).
  • The unauthenticated remote code execution (RCE) flaw, rated 9.8 CVSS, targeted the Environment Management Hub (PSEMHUB) component in PeopleTools versions 8.61 and 8.62.
  • The campaign, active from May 27 to June 9, 2026, primarily impacted the higher education sector, with at least one university confirming data theft.
  • Oracle released an emergency advisory on June 10, 2026, and organizations are urged to apply the patch immediately.

A sophisticated compromise and extortion campaign, attributed to the notorious threat actor UNC6240, known publicly as ShinyHunters, has targeted Oracle PeopleSoft infrastructure. Mandiant and the Google Threat Intelligence Group (GTIG) issued a joint critical warning detailing the operation, which leveraged a zero-day vulnerability for unauthenticated remote code execution.

Table Of Content

  • Key Takeaways
  • Oracle PeopleSoft 0-Day RCE Vulnerability
  • What You Should Do

The attackers exploited CVE-2026-35273, a severe vulnerability with a CVSS score of 9.8, before Oracle could release its official advisory on June 10, 2026. This allowed ShinyHunters to gain unauthorized access and initiate data exfiltration.

Between May 27 and June 9, 2026, the campaign actively targeted the Environment Management Hub (PSEMHUB) component within Oracle PeopleSoft PeopleTools versions 8.61 and 8.62. The attackers systematically compromised vulnerable systems during this period.

GTIG identified over 100 global organizations with IP addresses correlating to potentially vulnerable endpoints. A significant majority, 68%, of these potential victims were concentrated within the higher education sector, including numerous universities and colleges worldwide.

The University of Nottingham publicly confirmed unauthorized activity on its systems, reporting the theft of approximately 40 gigabytes of sensitive data. This stolen information reportedly included student records, financial aid data, health records, and immigration details.

Oracle PeopleSoft 0-Day RCE Vulnerability

As part of their investigation, GTIG meticulously triaged five sequential attacker-controlled staging IP addresses, ranging from 142.11.200.186 to 142.11.200.190. Each of these IP addresses hosted a Python SimpleHTTP server on port 8888, revealing critical operational details.

These exposed directories contained a trove of attacker command histories, staging materials, and pre-configured MeshCentral remote management agents, providing insight into the group’s tactics.

The Windows agent binaries were cleverly disguised as legitimate Microsoft Azure services, specifically named meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe. These agents were hardcoded to establish command-and-control (C2) communications with wss://azurenetfiles.net:443/agent.ashx, a domain carefully crafted to mimic legitimate Microsoft Azure NetApp Files endpoints and evade detection.

The attackers established their staging environment on May 27, 2026, at 22:14 UTC, by installing MeshCentral v1.1.59. Shortly after, at 22:25 UTC, they installed the acme-client npm package to automate the provisioning of Let’s Encrypt SSL certificates for their masquerading domain, enhancing the legitimacy of their infrastructure.

Utilizing the meshctrl.js command-line interface, the threat actors executed targeted reconnaissance commands on compromised hosts. They mapped Oracle PeopleSoft configurations by inspecting psappsrv.cfg, audited active NFS mounts, and read WebLogic config.xml files to comprehensively map internal application servers within the victims’ networks.

Lateral movement within the compromised environments was automated through a custom propagation script, named [victim_abbreviation]_fanout.sh, which was deployed to the /tmp directory. This script performed SSH credential spraying against internal hosts identified from /etc/hosts files.

Upon successful authentication, the script deployed a defacement and extortion marker file, named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT, into the WebLogic and Process Scheduler directories, clearly signaling the breach to the victims.

Exfiltrated data was efficiently compressed using zstd before the attackers established an outbound SSH connection to 176.120.22.24. This IP address hosted the public mirror of the ShinyHunters Data Leak Site (DLS), where the stolen data archives were subsequently published on June 9, 2026.

What You Should Do

  • Immediately apply Oracle’s emergency advisory for CVE-2026-35273 to all affected PeopleSoft installations.
  • Ensure all Oracle PeopleSoft instances are running actively supported versions and have all Critical Patch Updates (CPUs) applied without delay.
  • Review network logs for connections to the Indicator of Compromise (IOC) IP addresses and domains listed above.
  • Scan systems for the presence of the identified MeshCentral agent binaries and the extortion marker file.
  • Implement robust network segmentation to limit lateral movement in case of a breach.
  • Conduct a thorough audit of all PeopleSoft configurations, user accounts, and access privileges.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchThreatVulnerabilityzero-day

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

CISA Mandates Federal Agencies Patch Critical Ivanti EPMM Flaws in 3 Days

Next Post

Critical Microsoft Teams Android Vulnerability Exposes User Data

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Windows Hello for Business Bug Lets Attackers Impersonate Users in Entra ID
August 7, 2026
Critical Zapscape KVM Vulnerability CVE-2026-64561 Allows Guest-to-Host Escape
August 7, 2026
Chrome 101 Patches 41 Vulnerabilities, 6 Critical Memory Bugs
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us