
A significant vulnerability in Oracle's PeopleSoft software has been actively exploited by one of the world's most notorious ransomware groups, known as ShinyHunters. This group has reportedly targeted around 100 organizations, successfully extorting at least one victim by threatening to release stolen data. The vulnerability, identified as CVE-2026-35273, has a critical severity rating of 9.8 out of 10, marking it as one of the most severe zero-day vulnerabilities detected this year. According to researchers from Google’s Mandiant security team, the flaw is classified as a server-side request forgery (SSRF), which allows attackers to send requests from a vulnerable server to other systems within the targeted organization. Oracle has acknowledged the issue, stating that the SSRF vulnerability is remotely exploitable and has issued a temporary mitigation solution. However, a complete patch for the flaw has not yet been rolled out. Meanwhile, Mandiant has confirmed that victims of the attacks are facing extortion demands from the group. Among the affected entities, the University of Nottingham recently confirmed that it had fallen victim to the breach, resulting in a “significant” amount of student data being compromised. This announcement followed ShinyHunters' claim that the university was among its latest targets, as they released gigabytes of data purportedly obtained from the hack. Since May 27, ShinyHunters has been exploiting this vulnerability, and as of mid-week, they had targeted approximately 300 endpoints across 100 organizations, with around 68% of these belonging to the higher education sector. Researchers have noted that the group has exposed several directories that indicate ongoing attacks on PeopleSoft, and they have even left a staging server accessible, containing tools used during the attack.
The global ban on substances that deplete the ozone layer is widely viewed as a successful environmental initiative that...
Ars Technica | Jun 29, 2026, 19:05
In a significant ruling on Monday, the Supreme Court affirmed that the Fourth Amendment guards an individual's "location...
Ars Technica | Jun 29, 2026, 20:05
In a remarkable shift within the U.S. energy landscape, preliminary reports reveal that solar power has officially eclip...
Ars Technica | Jun 29, 2026, 20:15
In a significant move to combat cyber threats, federal authorities have announced a reward of up to $10 million for info...
Ars Technica | Jun 29, 2026, 22:10
Base44, the innovative vibe coding platform snapped up by Wix for $80 million just a year ago, is making headlines with ...
TechCrunch | Jun 30, 2026, 02:45