PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data

2026-06-14T08:51:44Zfd2bcb9124ccc65a0a76024baf328078972d730d59e5a0cd654e34d23a871ec6
AI agentsAI chatbotBadHostBitLocker bypassDashlaneLinux kernelMetaMicrosoftNPMOraclePeopleSoftRed HatRussiaSSD side-channelStarletteUSB device exploit (hardware)Windows 11account takeoverbotnetcredential stealerdata exfiltrationpassword managersupply chainuse-after-freezero-day

What happened

A batch of high‑impact security incidents and vulnerabilities reported by Ars Technica in May–June 2026: a critical PeopleSoft 0‑day used to steal gigabytes from hundreds of organizations; multiple other zero‑days (including a Windows 11 BitLocker bypass and a Microsoft zero‑day that was patched after disclosure); a Linux kernel use‑after‑free triggered by a single character; a critical vulnerability (“BadHost”) in the Starlette package affecting millions of AI agents; widespread software supply‑chain compromises (backdoored Red Hat NPM packages, TeamPCP poisoning open‑source code); credential

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
fd2bcb9124ccc65a0a76024baf328078972d730d59e5a0cd654e34d23a871ec6
Enrichment time
2026-06-14T08:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.