ctipilot.ch

ShinyHunters PeopleSoft campaign

campaign · campaign:shinyhunters-peoplesoft-2026

ShinyHunters Oracle PeopleSoft data-theft campaign: 100+ organizations, ~300 instances, education-heavy victimology; University of Nottingham confirmed.

Coverage timeline
4
first 2026-06-11 → last 2026-06-22
Peak priority
critical
1 critical · 3 notable
Sources cited
14
9 hosts
Sections touched
3
updates, weekly-sector-patterns, weekly-vuln-rollup
Co-occurring entities
2
see Related entities below
ATT&CK techniques
3
pinned v19.1 · see below
2026-06-124 appearances2026-06-22

ATT&CK techniques

3 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-06-12/shinyhunters-peoplesoft-campaign-oracle-confirms-cve-2026-35 · ATT&CK page ↗

Lateral Movement TA0008

T1021Remote Services×1

Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.

Evidence: 2026-06-12/shinyhunters-peoplesoft-campaign-oracle-confirms-cve-2026-35 · ATT&CK page ↗

T1021.004Remote Services: SSH×1

Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user.

Evidence: 2026-06-12/shinyhunters-peoplesoft-campaign-oracle-confirms-cve-2026-35 · ATT&CK page ↗

Story timeline

  1. 2026-06-22Public administration — named European institutions and government data in the firing line
    weekly-sector-patterns
  2. 2026-06-22Education — exposed CMS and forum software stack a structural risk
    weekly-sector-patterns
  3. 2026-06-22CVE-2026-46978 / CVE-2026-35278 — Oracle June 2026 CSPU: unauthenticated Solaris RAD flaw (10.0) and PeopleSoft RCE (9.8)
    weekly-vuln-rollup
  4. 2026-06-12ShinyHunters PeopleSoft campaign — Oracle confirms CVE-2026-35273 and ships an out-of-band patch; Nottingham quantifies 455,000 records
    updates

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

attributed to

Where this entity is cited

  • weekly-sector-patterns2
  • updates1
  • weekly-vuln-rollup1

Source distribution

  • securityweek.com3 (21%)
  • attack.mitre.org2 (14%)
  • bleepingcomputer.com2 (14%)
  • oracle.com2 (14%)
  • cloud.google.com1 (7%)
  • drupal.org1 (7%)
  • joomlacontenteditor.net1 (7%)
  • nottingham.ac.uk1 (7%)
  • other1 (7%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (14)

Entries about ShinyHunters PeopleSoft campaign (4)

2026-06-22 · view entry permalink →

NOTABLE

Education — exposed CMS and forum software stack a structural risk

Education entities sat under two pressures this week: the continuing ShinyHunters PeopleSoft campaign that W24 documented landing disproportionately on universities, and a cluster of critical web-application CVEs in software ubiquitous across European universities and student communities — JCE for Joomla (CVE-2026-48907, exploited), phpBB (CVE-2026-48611), Drupal core (CVE-2026-55803, BSI critical) and LiteSpeed shared-hosting (CVE-2026-54420, exploited), all in § 3. The pattern is not a single incident but an attack-surface concentration: the open-source CMS/forum/hosting stack that the education sector runs widely all took critical, partly-exploited disclosures in one week.

synthesis22 Jun 00:14Zmulti-sourceOpen finding ↗

2026-06-22 · view entry permalink →

NOTABLE

Public administration — named European institutions and government data in the firing line

The public sector again carried high-severity activity on multiple vectors. The Council of Europe — a Strasbourg human-rights body of which Switzerland is a member — was named in the ShinyHunters PeopleSoft campaign (§ 2). Iran-aligned Handala breached California Water Service through an internet-exposed RTKBase GNSS platform, leaking billing PII for ~2M customers though without OT access (SecurityWeek, 2026-06-14; daily 06-15). Texas Parks & Wildlife disclosed a third-party-vendor breach exposing 3.08M licence holders' names and driver's-licence numbers (BleepingComputer, 2026-06-18; daily 06-21). And the recurring lesson for CH/EU administration is the PTC Windchill emergency (§ 1), where the BSI's after-hours calls underline how government CERTs are now treating internet-exposed public-sector and industrial software.

synthesis22 Jun 00:14Zmulti-sourceOpen finding ↗

2026-06-22 · view entry permalink →

CVE-2026-46978 / CVE-2026-35278 — Oracle June 2026 CSPU: unauthenticated Solaris RAD flaw (10.0) and PeopleSoft RCE (9.8)

Oracle's June Critical Security Patch Update shipped 245 fixes on 2026-06-17, around 100 remotely exploitable without authentication, headlined by an unauthenticated Solaris Remote Administration Daemon flaw (CVE-2026-46978, CVSS 10.0) and a PeopleSoft RCE (CVE-2026-35278, 9.8) (Oracle CSPU; daily 06-18). The PeopleSoft fix lands in the middle of the ShinyHunters PeopleSoft campaign (§ 2) — prioritise PeopleSoft and any internet-reachable Solaris RAD instances.

vulnerability22 Jun 00:14Zmulti-sourceOpen finding ↗

Earlier coverage (1)