What We Know
REST OF WORLD:Constitutional Court vote may influence Puigdemont’s arrest warrant and return to CataloniaGAMING:Control Resonant’s launch hotfix eases combat and strengthens Dylan’s early progressionSPORTS:Maple Leafs acquire Kirill Marchenko from Blue Jackets and sign him to six-year extensionMARKETS:August U.S. Inflation Rose Less Than Expected as Spending Stayed Strong and Price Pressures PersistedCYBERSECURITY:Citrix NetScaler zero-days prompt global alerts and urgent mitigation effortsPOLITICS:Iran-US Nuclear and Hormuz Discussions Continue Amid Mediation and Doubts Over a DealAI:The EU advances AI Act enforcement as draft rules and provider letters emergeTOP STORIES:Ukraine develops affordable interceptor drones as jet-powered threats expose defense gapsREST OF WORLD:Constitutional Court vote may influence Puigdemont’s arrest warrant and return to CataloniaGAMING:Control Resonant’s launch hotfix eases combat and strengthens Dylan’s early progressionSPORTS:Maple Leafs acquire Kirill Marchenko from Blue Jackets and sign him to six-year extensionMARKETS:August U.S. Inflation Rose Less Than Expected as Spending Stayed Strong and Price Pressures PersistedCYBERSECURITY:Citrix NetScaler zero-days prompt global alerts and urgent mitigation effortsPOLITICS:Iran-US Nuclear and Hormuz Discussions Continue Amid Mediation and Doubts Over a DealAI:The EU advances AI Act enforcement as draft rules and provider letters emergeTOP STORIES:Ukraine develops affordable interceptor drones as jet-powered threats expose defense gaps
Older than 2 weeksJust now

ShinyHunters Oracle PeopleSoft Breach: 100+ Orgs

  • 8 sources analyzed
  • Source mix: Web
  • Momentum: Older than 2 weeks

What We Know

Multiple security write-ups and reporting say a critical unauthenticated remote-code-execution vulnerability in Oracle PeopleSoft (tracked as CVE-2026-35273) was exploited in June 2026. ToolsLib and other technical write-ups describe the flaw as allowing an attacker to issue a single unauthenticated HTTP request to gain access; vendors and security vendors published detection guidance and alerts after the issue emerged.

Reporting and industry blogs attribute the exploitation to the data-theft group ShinyHunters, which claims successful intrusions against over 100 organizations during a roughly two-week window in June 2026. A TechRadar report cites the U.S. National Association of Insurance Commissioners (NAIC) confirming a breach and quotes ShinyHunters’ claim of roughly 3.1 TB of data stolen. Other accounts and blogs note that affected victims include higher-education institutions and at least one international body (reporting links this incident to a Council of Europe disclosure involving employee records). Security vendors such as HookProbe and others published detection and mitigation guidance after the vulnerability was publicly discussed.

Source Comparison

Aligned reporting
7 corroborates - 0 adds context - 0 conflicts