ShinyHunters is at it again, this time using an Oracle zero day vulnerability to target over 100 global organizations in May and June, with more than half of these in the higher education sector.

A new report by Mandiant and Google Threat Intelligence Group researchers identified the activity, which they said occurred between May 27 and June 9. The vulnerability in question (CVE-2026-35273) is a critical remote code execution flaw in Oracle PeopleSoft PeopleTools, the underlying application framework and development platform that powers Oracle's PeopleSoft business applications. Specifically, it exists in its Updates Environment Management component used to manage and update PeopleSoft environments. Oracle released patches for the flaw this week.

“The exploitation of this vulnerability directly aligns with the observed targeting of Environment Management Hub (PSEMHUB) endpoints,” said researchers in a Thursday analysis. “Because this activity predates Oracle's June 10, 2026 advisory, the vulnerability was exploited as a zero-day.”

Notably, the threat actor’s staging infrastructure hosted pre-configured MeshCentral agent binaries. The agent for MeshCentral, an open-source remote management server, runs on remote devices to enable remote management. These binaries were masked as Azure services (called meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe); they were hardcoded to establish communication with the command and control (C2) attacker server. This allowed them to remotely execute commands while blending into normal administrative activity.

“Because this activity predates Oracle's June 10, 2026 advisory, the vulnerability was exploited as a zero-day.”

ShinyHunters published data leaks of stolen organization data earlier this week on June 9; researchers said that this campaign correlates with this data leak.

“While several organizations successfully blocked the activity or remediated the vulnerabilities, others experienced compromise, resulting in stolen data being published on the ShinyHunters DLS,” said researchers.

ShinyHunters have exploited Oracle flaws before; in October 2025 they targeted another Oracle EBS bug (CVE-2025-61884). The group, which has been around since around 2020, is known for their high-profile data theft and extortion attacks targeting cloud and enterprise platforms. Security researchers have connected the group to campaigns involving cloud services, SaaS platforms, and widely used enterprise software, including Oracle’s.

Researchers urged businesses to apply updates to address CVE-2026-35273, which is remotely exploitable sans authentication and can result in remote code execution. 

“In alignment with Oracle’s security advisory, we consider the implementation of these mitigations to be a high-priority risk reduction measure and strongly recommend immediate action to address the identified exposure,” they said.