Oracle PeopleSoft RCE Flaw Used as Zero-Day in Ongoing ShinyHunters Campaign
2026-06-12T14:51:51Z•b949530c144ded0155b477a1d5c36491925378eb7d227649c8191fb477dc95c8
BitLocker-bypassCISA-KEVChaotic-EclipseFortinetIoT-exposureIvantiJDY-botnetMicrosoft-DefenderOnyxC2Oracle-PeopleSoftRoguePlanetShinyHuntersWinRARactive-exploitationbotnetcamerasmalware-as-a-servicepatchingprivilege-escalationremote-code-executionstealerzero-day
What happened
Multiple high-impact threats and active exploitations were reported: a critical Oracle PeopleSoft zero-day was used by ShinyHunters to breach 100+ organizations (mostly universities); Ivanti Sentry RCE (CVE-2026-10520) is being actively exploited to gain root on exposed gateways; Fortinet patched a critical FortiSandbox command-injection (CVE-2026-25089, CVSS 9.8) being weaponized; and Russian-linked groups continue exploiting WinRAR path-traversal (CVE-2025-8088) via phishing. Additional notable items include OnyxC2 (Malware-as-a-Service stealer with DLL sideloading and HVNC), Chaotic Eclipse
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- b949530c144ded0155b477a1d5c36491925378eb7d227649c8191fb477dc95c8
- Enrichment time
- 2026-06-12T14:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.