Oracle PeopleSoft Zero-Day: ShinyHunters Spent 14 Days Inside University Networks Before Oracle Said a Word
CVE-2026-35273 — CVSS 9.8, no credentials, no user interaction — gave ShinyHunters 14 days of uncontested access to Oracle PeopleSoft infrastructure before Oracle published a single word of warning. ~300 installations compromised. 100+ organizations. 68% universities. University of Nottingham: 500,000 student records stolen. Mandiant confirmed the gadget chain. Data published June 9. Advisory dropped June 10.
Read Full Brief →Threats & Attacks
No credentials. No user interaction. ShinyHunters compromised ~300 PeopleSoft installations across 100+ organizations for 14 days before Oracle said a word. 68% universities. 500,000 student records from University of Nottingham. Data published before the advisory.
Largest Patch Tuesday in history. Wormable HTTP.sys CVSS 9.8. MiniPlasma patched. 83 RCE flaws. Then RoguePlanet — new unpatched Windows Defender SYSTEM zero-day with working public PoC. Secure Boot expires June 26.
Depthfirst’s autonomous agent scanned 1.5M lines of C. 21 confirmed zero-days each with reproducible PoC. One bug from 2003. FFmpeg is in your browser, streaming apps, and media pipeline. All fixed upstream — your embedded copies are not.
GHOST STADIUM phishing operation. Banking trojans in fake streaming apps. Rogue Wi-Fi at match venues. FBI, Group-IB, Kaspersky, Bitdefender all warning. Every attack vector explained.
Microsoft documented how a hidden GitHub issue comment tricked Claude into reading /proc/self/environ and exfiltrating all CI/CD runner secrets. Patched in v2.1.128. The “Comment and Control” class affects all major AI agents.
Command injection in SD-WAN Manager CLI. Root via crafted file upload. No patch, no timeline. Chains after CVSS 10.0 auth bypass. Mandiant found it during active exploitation.
Intelligence & Deep Dive
Further Coverage
Unauthenticated attackers forge GlobalProtect cookies, bypass MFA, establish VPN sessions. CVSS 9.1. Rapid7 confirmed exploitation. Federal deadline June 19.
Nx Console breach + Megalodon GitHub Actions campaign. TeamPCP open-sourced its framework. Copycat groups active. Full forensic checklist inside.
22,052 incidents. Ransomware in 44%. Supply chain attacks doubled. Median exploit timeline 5 days vs 43-day patch time.
Also discovered during active exploitation — the security tool becomes the attack vector. CISA KEV. June 4 deadline.
Four DTLS packets. No credentials. Full admin. Nation-state-linked UAT-8616. CISA Emergency Directive 26-03.
NSA and CISA have 60 days to build a classified AI cyber benchmark. Triggered by Anthropic Mythos autonomous vulnerability discovery. DOJ to prioritize AI-enabled attack prosecution.
The DataWater Intelligence Brief
Weekly CISO-level threat analysis — breaking vulnerabilities, technical depth, zero noise. Trusted by enterprise and government security leaders.
