PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data

2026-06-14T20:51:48Z705da26b01ee0ac2ae834e07a9035eaf02355860b1a4ea48ade4b772e762b493
ai-chatbot-exploitbadhostbitlocker-bypassbotnet-takedowncisa-credentialscredential-stealercriticaldashlanedata-exfiltrationexploit-disclosurefirmware-exploitlinux-kernelmicrosoftnpm-backdoororaclepassword-managerpeoplesoftred-hatstarlettesupply-chain-compromiseusb-infectionuse-after-freezero-day

What happened

Ars Technica's security feed highlights a wave of high-risk incidents: a PeopleSoft zero-day actively used to steal gigabytes from hundreds of organizations; multiple vendor zero-days (including a Windows 11 BitLocker bypass and a Microsoft-disclosed patch race); a Linux-kernel use-after-free triggered by a single character enabling sandbox escape/root; and a critical vulnerability in Starlette ("BadHost") threatening millions of AI agents. The feed also documents widespread supply-chain and credential theft activity—Red Hat packages backdoored via an official NPM channel, dozens of Microsoft/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
705da26b01ee0ac2ae834e07a9035eaf02355860b1a4ea48ade4b772e762b493
Enrichment time
2026-06-14T20:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.