PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data

2026-06-13T08:51:49Z7328871549ea61c82e3f707c30b2eae9ab31883c5b78a645040aa07c28377453
AI-securityBadHostBitLockerChromiumDashlaneLinux kernelMetaMicrosoftNPMOraclePeopleSoftRed HatStarletteWindows 11chatbot-exploitcredential-stealercredentials-leak (CISA)data-exfiltrationexploit-codeopen-source compromisepassword-vaultroot escalationsupply-chainuse-after-freezero-day

What happened

A collection of high-impact security stories from Ars Technica: a critical PeopleSoft 0‑day (Oracle) is being used to steal gigabytes from hundreds of organizations; multiple high‑severity/zero‑day flaws reported in Microsoft products (including one patched after researcher disclosure) and a Windows 11 BitLocker bypass; a single‑character use‑after‑free in the Linux kernel enabling sandbox escape/root; mass credential‑stealing malware found in Microsoft packages and dozens of Red Hat packages backdoored via the official NPM channel (supply‑chain compromise); Dashlane users had encrypted vaults

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
7328871549ea61c82e3f707c30b2eae9ab31883c5b78a645040aa07c28377453
Enrichment time
2026-06-13T08:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.