PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data

2026-06-15T08:51:48Z75a2bbf4802d629d15759b64141e64adae4b4b110ec1c66616e6e7aaeee227c0
AI-chatbotBadHostBitLocker-bypassCISA-credentials-leakChromiumDashlaneLinux-kernelMetaMicrosoftOraclePeopleSoftSSD-side-channelStarletteUSB-malwarebotnetcredential-stealerexploit-codenpmopen-source-poisoningprompt-injectionsupply-chainzero-day

What happened

Ars Technica's late May–June 2026 security feed aggregates multiple high-impact, actively exploited incidents and supply-chain compromises: a PeopleSoft zero-day used to steal gigabytes from hundreds of organizations; Microsoft and Linux kernel zero-days reported and being patched; a critical vulnerability in the Starlette package affecting millions of AI agents; backdoored Red Hat packages distributed via npm and a broader campaign of open-source poisoning (TeamPCP); Microsoft-distributed packages containing credential-stealers; Dashlane vault downloads by attackers; exploit code published (e

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
75a2bbf4802d629d15759b64141e64adae4b4b110ec1c66616e6e7aaeee227c0
Enrichment time
2026-06-15T08:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.