ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day

2026-06-12T07:24:00Z0b96a7bbff628a65db5446605a84be2b80ac7fe2278fd90d0a82f1fbb8acc40c
AI-powered attacksBitLocker bypassCheck Point VPNChrome zero-dayCisco SD‑WANGitHubHTTP/2 DoSIvanti SentryMiasma wormNSO Group','WhatsApp','credential theft','Active Directory','exfiNightmare EclipseOpenAI CodexOracle PeopleSoftQilinRCEShinyHuntersWindowsWorld Food Programmedata breachnpm auto-runransomwarerootself‑spreading wormsupply chainzero-day

What happened

A wave of active zero‑day exploitation, high‑impact breaches and AI‑enabled attack tooling was reported by The Register in early June 2026. Notable incidents include ShinyHunters claiming an Oracle PeopleSoft 0‑day affecting 100+ organisations (University of Nottingham named), multiple Windows 0‑days and a claimed BitLocker bypass (Nightmare Eclipse/other leak publishing), critical unauthenticated RCEs in Ivanti Sentry, a patched Check Point VPN 0‑day that was already exploited, an unpatched Cisco SD‑WAN 0‑day under attack, and Chrome’s fifth exploited zero‑day this year. Supply‑chain and worm

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
0b96a7bbff628a65db5446605a84be2b80ac7fe2278fd90d0a82f1fbb8acc40c
Enrichment time
2026-06-12T07:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day · Baitaphish