Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks
2026-06-11T19:24:06Z•6b8057bcf83b8f4f72e4e071664e0fe8c12c814b50bafc8ab540b725f7637913
BitLockerCISA BOD 26-04CVE-2026-35273China targetingDesigo CCFBI website seizuresGreatXMLKEVLangflowMicrosoft Defender offline scanOnyxC2OraclePalo Alto NetworksPeopleSoftRCEShinyHuntersSiemensSplunkUniversity of Nottinghamalert fatigue','AI automationdata breachfalse positivesstealervulnerability managementzero-day
What happened
SecurityWeek roundup: Oracle released mitigations for a PeopleSoft vulnerability (CVE-2026-35273) amid reports of possible zero-day exploitation linked to ShinyHunters; researchers disclosed a ‘GreatXML’ zero‑day PoC that can bypass BitLocker by abusing Microsoft Defender offline scanning to obtain a SYSTEM shell; Splunk and Palo Alto Networks patched severe vulnerabilities enabling arbitrary file creation and protected-resource modification; Langflow RCE exploitation (unauthenticated arbitrary file write) is being abused in the wild; OnyxC2 stealer is being marketed as a $250/month enterprise
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 6b8057bcf83b8f4f72e4e071664e0fe8c12c814b50bafc8ab540b725f7637913
- Enrichment time
- 2026-06-11T19:24:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.