PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data

2026-06-13T20:51:45Zf060f90493848c073773d0f5c572c469fe7cb94f6276edf35edf09e6470761fa
BadHostBitLockerCISA-credentials-leakDashlaneLinux-kernelMeta-AIMicrosoftOraclePeopleSoftRed-HatSSD-trackingStarletteTeamPCPUSB-malwareaccount-takeoverbotnetcredential-stealerdata-exfiltrationnpmopen-source-vulnerabilitypackage-backdoorpassword-vault-theftsupply-chain-attackuse-after-freezero-day

What happened

The feed is dominated by a critical Oracle PeopleSoft zero-day that has been used to steal gigabytes of data from hundreds of organizations. Other high‑priority incidents include multiple disclosed zero‑days (Microsoft, a Windows 11 BitLocker bypass), a Linux kernel use‑after‑free leading to sandbox escape, a critical open‑source flaw in Starlette ('BadHost') impacting millions of AI agents, and several supply‑chain/backdoor incidents (Red Hat packages backdoored via npm, TeamPCP campaign). Additional notable items: credential‑stealing packages distributed in Microsoft packages, Dashlane vault

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
f060f90493848c073773d0f5c572c469fe7cb94f6276edf35edf09e6470761fa
Enrichment time
2026-06-13T20:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.