PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data
2026-06-14T08:51:44Z•fd2bcb9124ccc65a0a76024baf328078972d730d59e5a0cd654e34d23a871ec6
AI agentsAI chatbotBadHostBitLocker bypassDashlaneLinux kernelMetaMicrosoftNPMOraclePeopleSoftRed HatRussiaSSD side-channelStarletteUSB device exploit (hardware)Windows 11account takeoverbotnetcredential stealerdata exfiltrationpassword managersupply chainuse-after-freezero-day
What happened
A batch of high‑impact security incidents and vulnerabilities reported by Ars Technica in May–June 2026: a critical PeopleSoft 0‑day used to steal gigabytes from hundreds of organizations; multiple other zero‑days (including a Windows 11 BitLocker bypass and a Microsoft zero‑day that was patched after disclosure); a Linux kernel use‑after‑free triggered by a single character; a critical vulnerability (“BadHost”) in the Starlette package affecting millions of AI agents; widespread software supply‑chain compromises (backdoored Red Hat NPM packages, TeamPCP poisoning open‑source code); credential
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- fd2bcb9124ccc65a0a76024baf328078972d730d59e5a0cd654e34d23a871ec6
- Enrichment time
- 2026-06-14T08:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.