ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

From Mandiant and Google Threat Intelligence Group an advisory Mandiant and Google Threat Intelligence Group GTIG have identified an active compromise and extortion campaign attributed to UNC6240 ShinyHunters targeting Oracle PeopleSoft application infrastructure The activity was observed between May 27 2026 and June 9 2026 and is consistent with the exploitation of CVE202635273 a critical remote Source