Why Security Teams Need To Start Earlier
2026-06-19T07:23:44Z•8a6702d7c430ef3f16e999054eea652c40ce818ae56a173b6acd63c9fe8c3295
AICVE-2026-35273DLL sideloadingDonutMetasploitNIS2RATTTPscompliancedropping-elephantin-memoryiocmalwareoraclepatchingpeoplesoftremote code executionssrfthreat-huntingvulnerability-managementzero-day
What happened
This Rapid7 feed highlights two high-priority security topics and several operational guidance items. First, an actively exploited Oracle PeopleSoft zero-day (CVE-2026-35273) in PeopleTools 8.61/8.62 enables unauthenticated remote code execution (CVSSv3.1 9.8) via a server-side request forgery; Oracle published an out-of-band patch on 2026-06-10 and immediate remediation is urgent. Second, researchers tracked a sophisticated Dropping Elephant malware campaign using a China-themed decoy and advanced loader tradecraft: DLL side-loading with a legitimate Microsoft binary (Fondue.exe), Donut shell
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 8a6702d7c430ef3f16e999054eea652c40ce818ae56a173b6acd63c9fe8c3295
- Enrichment time
- 2026-06-19T07:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.