
ShinyHunters UNC6240 Exploits CVE-2026-35273 Zero-Day in Oracle PeopleSoft, Hits 68% Higher Education Targets
ShinyHunters used a zero-day in Oracle PeopleSoft to breach universities, with 68% of targeted endpoints in higher education. Mandiant traced infrastructure left exposed by the actors. The incident highlights recurring exposure of academic enterprise systems to extortion groups.
The campaign centered on exposed /PSEMHUB/hub endpoints reachable over HTTP. Attackers deployed MeshCentral agents disguised as Azure binaries, used [victim]_fanout.sh for SSH lateral movement via hardcoded credentials, and exfiltrated compressed archives via outbound SSH to azurenetfiles.net. Mandiant identified five sequential IPs running SimpleHTTP on port 8888 with exposed .bash_history and staging files. This infrastructure exposure allowed public mapping of the operation.
Mandiant notified over 100 organizations matching vulnerable endpoints, with 68 percent in higher education. The University of Nottingham breach exposed 455,000 records including passport numbers and disability data. Oracle's mitigation requires disabling PSEMHUB or blocking /PSEMHUB/* paths, yet WebLogic access logs and XMLDecoder persistence in envmetadata remain viable detection points. Academic environments show higher exposure rates due to legacy multi-server deployments and delayed patching cycles.
The pattern reveals systematic targeting of higher education infrastructure where enterprise software like PeopleSoft is common yet perimeter controls lag. ShinyHunters shifted from credential dumps to direct zero-day extortion, leveraging the same under-monitored service exposure seen in prior education sector incidents. Official attribution to UNC6240 rests on tooling overlap rather than independent infrastructure confirmation.
Next steps include perimeter blocking of /PSIGW/HttpListeningConnector, log review for external POSTs to PSEMHUB, and monitoring for additional leak site postings. Universities without support contracts face extended risk windows until patches propagate.
Mandiant: At least 15 additional universities among the 100 notified will confirm data exfiltration on public leak sites within 45 days.
Sources (3)
- [1]The Hacker News(https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html)
- [2]Mandiant Threat Intelligence(https://www.mandiant.com/resources/blog/unc6240-peoplesoft-campaign)
- [3]Oracle Security Alert(https://www.oracle.com/security-alerts/)