Back to news
Tech/Europe
ShinyHunters cybercrime group exploits Oracle PeopleSoft zero-day
MULTIPLE REPORTS·Published ·Event date ·Main source · The Register
Story essentials
ShinyHunters
United Kingdom
June 9, 2026
Original reports
ShinyHunters exploited CVE-2026-35273 to compromise the University of Nottingham.
The breach resulted in the theft of 40 GB of personal and billing data.
Oracle issued an out-of-band security alert for the critical vulnerability.
This page is produced by collecting and structuring multiple public reports. Sections based only on reporting or testimony affect the displayed assessment, and the page is updated when new information is identified.
About this article
COMPAMIR Editorial Team
The COMPAMIR editorial team brings together public reporting and links to the original coverage. We update the page as new information emerges.
Read our editorial policyRelated book
Affiliate / Ad
Click Here to Kill Everybody: Security and Survival in a Hyper-connected World
Author: Bruce Schneier
This book provides a comprehensive look at the systemic risks of a hyper-connected world, explaining how vulnerabilities in enterprise software like Oracle PeopleSoft can be weaponized by cybercriminal groups to cause massive data breaches.
As an Amazon Associate, COMPAMIR earns from qualifying purchases.