Today's AI/ML headlines are brought to you by ThreatPerspective

Digital Event Horizon

The Devastating Consequences of a Critical PeopleSoft 0-Day Vulnerability



ShinyHunters exploits a critical PeopleSoft 0-day vulnerability to steal data from hundreds of organizations. The group uses this vulnerability for more than two weeks, breaching at least one organization and publishing stolen data on their DLS.

  • The recent security incident involved a ransomware group called ShinyHunters exploiting CVE-2026-35273, an SSRF vulnerability with a severity rating of 9.8 out of 10.
  • ShinyHunters managed to breach hundreds of organizations, stealing significant amounts of data, including student information from the University of Nottingham.
  • The attackers left behind a staging server containing tools used in the attack, revealing reconnaissance on compromised organizations and an outbound SSH connection to their Data Leak Site.
  • The incident highlights the importance of maintaining up-to-date security patches for widely used software systems like PeopleSoft.
  • Mandiant and Rapid7 have provided indicators of compromise and are advising PeopleSoft customers on steps to secure their systems.



  • A recent security incident has highlighted the devastating consequences of exploiting critical vulnerabilities in widely used software systems. The affected organization, Oracle-owned PeopleSoft, was targeted by a ransomware group known as ShinyHunters, which managed to steal significant amounts of data from hundreds of organizations.

    The vulnerability exploited, CVE-2026-35273, is classified as an SSRF (server-side request forgery) and carries a severity rating of 9.8 out of 10, making it one of the most critical vulnerabilities of the year. This critical flaw allows attackers to send requests from a susceptible server to systems used by targeted organizations, providing ShinyHunters with unfettered access to sensitive data.

    According to reports, ShinyHunters had been exploiting this vulnerability for more than two weeks prior to being flagged by Oracle. In that time, the group managed to breach at least one organization and obtained a significant amount of stolen data, which was then published on their DLS (Data Leak Site). The data in question included student information from the University of Nottingham, as well as data belonging to hundreds of other organizations across various sectors.

    Researchers have discovered that ShinyHunters left behind a staging server containing tools used in the attack. This server revealed that the attackers had performed reconnaissance on compromised organizations, mapping PeopleSoft configurations and viewing process scheduler and WebLogic server XML configurations. They also established an outbound SSH connection to 176.120.22.24, the IP address hosting ShinyHunters’ DLS.

    This incident highlights the importance of maintaining up-to-date security patches for widely used software systems like PeopleSoft. Despite this, ShinyHunters managed to breach hundreds of organizations and steal significant amounts of data in a short period of time. This underscores the need for vigilance and prompt action when dealing with such critical vulnerabilities.

    In light of this incident, Mandiant and Rapid7 have provided detailed indicators of compromise and are advising PeopleSoft customers on the steps they should take immediately to secure their systems.



    Related Information:
  • https://www.digitaleventhorizon.com/articles/The-Devastating-Consequences-of-a-Critical-PeopleSoft-0-Day-Vulnerability-deh.shtml

  • https://arstechnica.com/security/2026/06/peoplesoft-0-day-affecting-hundreds-of-organizations-steals-gigabytes-of-data/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-35273

  • https://www.cvedetails.com/cve/CVE-2026-35273/


  • Published: Fri Jun 12 15:08:13 2026 by llama3.2 3B Q4_K_M











    © Digital Event Horizon . All rights reserved.

    Privacy | Terms of Use | Contact Us