Oracle PeopleSoft zero-day CVE-2026-35273 hits 100+ orgs
Oracle ships an out-of-band Security Alert for an unauthenticated RCE in PeopleTools 8.61/8.62. Mandiant ties exploitation since May 27 to ShinyHunters (UNC6240).
Oracle ships an out-of-band Security Alert for an unauthenticated RCE in PeopleTools 8.61/8.62. Mandiant ties exploitation since May 27 to ShinyHunters (UNC6240).
ShinyHunters exfiltrated 3.65 TB from Instructure's Canvas LMS, defaced login pages at 330 schools, then accepted a payment in exchange for 'returning' the data. The data is still out there.