ShinyHunters Exploit a CVSS 9.8 Oracle PeopleSoft Zero-Day to Breach 100 Organizations — 68% Are Universities Because Academia Updates Its Infrastructure With the Urgency of a Tenured Professor

🤚 The Open-Palm Breach Report

ShinyHunters — the extortion gang that has been treating 2026 like a personal buffet of poorly secured enterprise software — has exploited a CVSS 9.8 zero-day in Oracle PeopleSoft to breach over 100 organizations across approximately 300 instances. The vulnerability, tracked as CVE-2026-35273, enables unauthenticated remote code execution against PeopleSoft PeopleTools versions 8.61 and 8.62. No credentials required. No user interaction needed. Just a network connection and the audacity to point it at an HR system that manages payroll for an entire university.

According to Mandiant, a staggering 68% of targeted victims are in the higher education sector — because if there’s one industry that reliably runs critical software with the update cadence of a geological epoch, it’s academia. The University of Nottingham has already been confirmed as a victim, with data on 450,000+ current and former students now decorating ShinyHunters’ leak site like a particularly depressing trophy case.

👐 The Two-Handed Exploit Chain

The technical details are a case study in why “defense in depth” remains a phrase most organizations use exclusively in PowerPoint presentations. ShinyHunters deployed a “gadget chain” combining legacy and zero-day vulnerabilities — a Rube Goldberg machine of exploitation, except instead of a marble triggering a domino that rings a bell, it’s an unpatched serialization flaw triggering a class loader that gives you root on a server containing 10,000 Social Security numbers.

Once inside, the attackers’ shell scripts demonstrated a workmanlike approach to lateral movement:

  • Parse /etc/hosts to identify PeopleSoft-related systems
  • Attempt SSH connections using common admin accounts: ‘psoft’, ‘oracle’, ‘linuxadm’
  • Try both password and key-based authentication
  • Deploy ransom notes to compromised servers

The infrastructure was traced to seven IP addresses (142.11.200[.]186-190, plus two others), with TLS certificates referencing “azurenetfiles[.]net” — a domain previously linked to ShinyHunters operations. In a detail that manages to be both brazen and hilarious, the attackers reportedly attempted to breach an FBI PeopleSoft portal and, for once, failed. Even ShinyHunters has a ceiling, and apparently it’s the Federal Bureau of Investigation.

🌿 The Gentle Awakening

PeopleSoft is one of those enterprise platforms that exists in a peculiar twilight zone of corporate IT. It’s too critical to turn off, too expensive to replace, and too deeply embedded to modernize. Universities run their entire student lifecycle on it — admissions, financial aid, payroll, HR. It is, in many cases, the single system that knows everything about everyone at the institution. And it was running a version of PeopleTools with an unauthenticated RCE bug that Oracle hadn’t patched yet.

This is ShinyHunters’ third major campaign of 2026. They hit Charter Communications in April (40 million records, via a phone call). They hit Carnival Cruise in May (6 million records, also via a phone call). Now they’ve graduated from social engineering to zero-day exploitation, which is the threat actor equivalent of getting a promotion and a corner office.

Oracle has released emergency mitigations but not a full patch — the corporate security equivalent of putting a towel under the door during a flood and promising to call a plumber next week.

👑 The Gold-Leaf Academic Discount

The 68% higher education targeting rate is the number that should keep CISOs awake tonight, though the ones at universities probably won’t because their security budget was reallocated to the new student wellness center. Universities are the perfect PeopleSoft victim: they run massive, complex deployments; they have small, overworked IT teams; they store extraordinarily sensitive data (student records, financial aid information, medical data, Social Security numbers); and they update their infrastructure with the urgency of a tenured professor approaching a deadline.

The combination of a CVSS 9.8 unauthenticated RCE, a threat actor with a proven track record of mass data exfiltration, and a victim pool that is structurally incapable of rapid patching is about as close to a perfect storm as cybersecurity gets. If your institution runs PeopleSoft and you haven’t applied Oracle’s emergency mitigations yet, the appropriate emotional response is not concern — it’s the kind of focused panic usually reserved for seeing your production database credentials in a public GitHub repository.

“The attackers tried to hack the FBI and failed, which means the FBI’s PeopleSoft admin is officially the most competent person in this entire story. The bar was on the floor and only one organization cleared it.” — The Slap of Wisdom Higher Education Security Bureau, currently updating its own student records system and finding three unauthorized SSH keys it doesn’t remember creating