National Law Review
6/19/2026

ShinyHunters Targeting Higher Education Sector
Short summary
ShinyHunters exploited an unpatched Oracle PeopleSoft zero-day (CVE-2026-35273) to breach 100+ organizations, with 68% in US higher education. The group is actively publishing stolen data. Implement Oracle's mitigation steps immediately while awaiting a patch.
- •Unpatched zero-day (CVE-2026-35273) in Oracle PeopleSoft allows remote code execution and server takeover
- •100+ organizations breached; 68% in US higher education sector; attackers publishing victim names and data
- •Campaign still active; patch not yet released; implement Oracle's mitigation steps immediately
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



