A Zero-Day, 100+ Victims, and a Very Bad Semester

A Zero-Day, 100+ Victims, and a Very Bad Semester

Universities spend a fortune teaching students about risk management. This summer, a hacking crew handed more than a hundred of them a brutal surprise pop quiz on the subject — and an uncomfortable number of them failed it badly. The syllabus, it turns out, did not cover this.

One Bug, Three Hundred Open Doors

The extortion group ShinyHunters exploited a critical flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it quiet. By June 10, the campaign had been confirmed across more than 300 instances at over 100 organizations worldwide. That is not a smash-and-grab; that is an industrial operation.

The vulnerability, CVE-2026-35273, is a remote code execution bug rated a terrifying 9.8 out of 10. It needs no login and no user interaction — just network access over HTTP — and Oracle did not publish its advisory until June 10, which means it was a live zero-day the entire time. For defenders, that is roughly the worst possible combination of traits.

Higher Education Took the Hardest Hit

Roughly 68% of the victims were in higher education, most of them in the United States. Google's Mandiant, which tracks the group as UNC6240, dated the intrusion activity to a window between May 27 and June 9 — about two quiet weeks of unhurried ransacking before anyone sounded the alarm.

The University of Nottingham has publicly acknowledged its breach, with around 454,600 current and former students' records published on the group's leak site. Have I Been Pwned counted some 455,000 unique email addresses, alongside names, addresses, phone numbers, passport numbers, and details on ethnicity and disabilities. That is not just spam-list fodder — those are identity-theft starter packs.

The Real Lesson Is About Patch Time

Zero-days are unavoidable; what actually matters is the gap between disclosure and defense. When a 9.8-rated bug circulates for weeks before an advisory even exists, defenders are fighting blindfolded while the attackers have the lights fully on and a map of the building.

The detail most coverage glosses over: this was extortion, not demolition. ShinyHunters did not want to break systems — it wanted leverage, and student data is exactly the kind of sensitive, heavily regulated, reputation-wrecking material that makes administrators reach for the checkbook. The cruelty is almost a business model.

Patch management is the most boring topic in tech right up until 455,000 people learn their passport number is sitting on a leak site. Then, suddenly, it is the only thing anyone cares about.

Source: The Hacker News