CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (12 June 2026)

Published: Loading…

At a Glance

  • UNC6240 ShinyHunters exploited CVE-2026-35273 in Oracle PeopleSoft Environment Management, enabling unauthenticated remote code execution across 300 instances affecting over 100 organisations globally.
  • The University of Nottingham confirmed a cyber incident following ShinyHunters data theft, exposing approximately 455,000 student and alumni email addresses alongside academic and financial records.
  • Oracle released an out-of-band security alert for PeopleSoft CVE-2026-35273 while investigations continued into limited exploitation and mitigations for enterprise deployments.
  • Europol dismantled the AudiA6 cryptocurrency laundering service linked to ransomware groups, freezing funds and seizing infrastructure used to process illicit proceeds across multiple jurisdictions.
  • Researchers demonstrated the FROST attack, using OPFS-based SSD timing side channels to infer application and website activity from browser-driven storage contention patterns.
  • Kyushu Electric Power disclosed a missing external storage device containing customer data for up to 10.9 million accounts after a physical security lapse in a server room.

Summary

The ShinyHunters campaign centred on Oracle PeopleSoft CVE-2026-35273, with exploitation enabling unauthenticated remote code execution across enterprise environments. Over 100 organisations were impacted, with activity concentrated in higher education sectors and multi-instance deployments. Oracle issued an out-of-band advisory as mitigation measures were deployed during active exploitation.

The University of Nottingham confirmed a cyber incident linked to ShinyHunters data theft activity affecting student and alumni records. Approximately 455,000 email addresses were exposed alongside personal, academic, and financial information. The breach forms part of wider targeting of education-sector systems using enterprise application vulnerabilities.

Europol coordinated the dismantling of the AudiA6 cryptocurrency laundering infrastructure used by ransomware groups. The operation disrupted financial flows totalling hundreds of millions of euros and included domain seizures and cryptocurrency freezes. Investigators identified extensive mule account networks supporting laundering operations.

Security researchers disclosed the FROST side-channel attack, leveraging SSD access timing through OPFS browser functionality. The method enables inference of application and website activity using storage contention patterns measured at high resolution. Machine learning models were used to classify behavioural activity from latency signals.

Physical and operational security failures were reported in the Kyushu Electric Power incident involving a missing storage device. The drive contained customer data for up to 10.9 million accounts including personal identifiers and utility usage records. Authorities were notified following internal investigation into access to secure server room infrastructure.

Highlights of the Day

ShinyHunters Exploit Oracle PeopleSoft Zero-Day in Education Campaign

UNC6240 (ShinyHunters) exploited CVE-2026-35273, a CVSS 9.8 remote code execution zero-day in Oracle PeopleSoft Environment Management between 27 May and 9 June 2026. Staging infrastructure used MeshCentral 1.1.59, Python SimpleHTTP servers, and Azure-masquerading agents hosted across sequential IPs 142[.]11[.]200[.]186–190 with azurenetfiles[.]net C2 domain infrastructure. GTIG notified over 100 organisations, 68 percent higher education in United States, after compromises linked to ShinyHunters Data Leak Site publication on 9 June 2026.

ShinyHunters Leak Exposes University of Nottingham Student Records

The University of Nottingham confirmed a cyber incident following data published by ShinyHunters, who claimed to have accessed internal systems and extracted significant student records. Analysis indicates approximately 455,000 unique email addresses were exposed alongside names, passports, contact details, and academic and financial information across students and alumni. The university stated that both current students and alumni are affected, and it is coordinating with Action Fraud, the Information Commissioner’s Office, and regulatory bodies.

Oracle Issues Emergency Fix for PeopleSoft Zero-Day Exploitation

Oracle released an out-of-band security alert addressing CVE-2026-35273, a critical PeopleSoft vulnerability affecting Enterprise PeopleTools versions 8.61 and 8.62 that can enable unauthenticated remote code execution. Reports indicate exploitation attempts targeting approximately 300 PeopleSoft instances across more than 100 organisations, with attackers allegedly chaining multiple vulnerabilities including zero-days to access enterprise data. The advisory follows activity attributed to ShinyHunters, with Oracle confirming mitigations are available while investigation into limited real-world exploitation remains ongoing.

APT28 Tradecraft Evolves Across Two Decades of GRU Operations

APT28 tradecraft analysis maps two decades of GRU Unit 26165 operations, detailing shifts in tooling, infrastructure, and targeting across multiple operational eras Recent phases show fragmented single-purpose malware, zero-click Outlook exploitation via CVE-2023-23397, and infrastructure shifted to compromised edge routers and SOHO devices Latest operations include Phantom Net Voxel in-memory Covenant deployments and LameHug, an LLM-driven infostealer querying cloud AI services for command execution

AI-Themed LNK Campaign Delivers AsyncRAT via Multi-Stage Loader

FortiGuard Labs observed a Windows campaign distributing AI-themed documents in compressed archives containing LNK files and hidden PDFs targeting users seeking AI resources. The infection chain uses LNK-based line extraction from disguised PDFs, staged PowerShell scripts, and AutoHotkey loaders to reflectively inject AsyncRAT into memory. Persistence is achieved through scheduled tasks, Realtek-themed services, and obfuscated scripts using multilingual variables, ultimately enabling AsyncRAT command-and-control communication and full system compromise.

Chinese Actors Target FIFA 2026 Ticket Fraud Operation

CloudSEK reported a Chinese-origin operation targeting FIFA World Cup 2026 ticket buyers with cloned sites and MitM phishing bypassing SMS OTP via tbpay.uk infrastructure. Infrastructure included typosquatted FIFA domains, multi-tenant reseller panels, tawk.to live chat, and card-skimming backend activity linked to Chinese IP 222[.]167[.]244[.]34 with Simplified Chinese interfaces. Data centre logs showed full victim journey tracking, including card CVV capture and OTP verification stages, with traffic from Facebook and Instagram in-app browsers.

Source: CloudSEK

GlobalProtect Authentication Bypass Exploited via CVE-2026-0257 Campaign

Arctic Wolf reported exploitation of CVE-2026-0257 affecting Palo Alto Networks PAN-OS GlobalProtect, enabling authentication bypass via forged cookies in late May–June 2026 campaigns. Suspicious activity originated from VPS hosting infrastructure, with cookie decryption failures followed by successful logins and IPsec VPN tunnel establishment on affected gateways. Sustained access in a subset of intrusions enabled Impacket-based SMB reconnaissance, NTLM authentication attempts, and limited internal network discovery following VPN session establishment.

Europol Dismantles AudiA6 Crypto Laundering Network

Europol-led operation dismantled AudiA6, a crypto laundering service linked to ransomware groups, responsible for processing over EUR 336 million between 2022 and 2025. Authorities arrested two suspects in Georgia, seized more than 30 servers and 25 domains, and froze EUR 692,000 in cryptocurrency assets during coordinated action. Investigators linked the operation to over 15 global cases and identified 6,000 KYC mule records connected to ransomware proceeds and Dark2Web forum infrastructure.

Source: Europol

FROST Attack Uses SSD Timing to Track Browser Activity

Researchers at Graz University of Technology demonstrated FROST, a browser-based side-channel attack that leverages Origin Private File System (OPFS) timing variations to infer user activity from SSD access delays. The technique measures contention on storage I/O operations to fingerprint application launches and website visits, achieving up to 661 bits per second covert channel throughput on Linux and 891 bits per second on macOS. Experimental results showed website identification accuracy of 88.95% and application detection accuracy of 95.83% using machine learning models trained on SSD latency patterns.

Kyushu Electric Reports Missing Drive Exposing 10.9 Million Records

Kyushu Electric Power disclosed the loss of an external storage device containing data belonging to up to 10.9 million customers after it went missing from a locked server room cabinet in late May 2026. The compromised drive held customer names, addresses, electricity usage data, telephone numbers, and retail electricity provider details, though the company confirmed no financial or card information was included. Internal checks identified 57 staff with access to the server room, and the company has reported the incident to Japanese authorities and the Personal Information Protection Commission.

Daily Coverage

Developments
Peoplesoft Zero-DayShinyhunters CampaignUniversity BreachAudia6 Takedown
Vulnerabilities
CVE-2026-50751Quantum Security Gateway R82.10 With Jumbo Hotfix Take 19 Or Below (Critical)CVE-2026-35273Peoplesoft Enterprise Peopletools 8.61 (Critical)CVE-2026-20253Splunk Enterprise 10.2 (Critical)CVE-2026-0257Pan-Os 12.1.0 (Critical)CVE-2023-23397CVE-2026-9266CVE-2026-11645
Threat Groups
OceanLotusAPT32 is a suspected Vietnambased threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.APT28[Also known as: Sofacy, Sednit, Pawn Storm, Forest Blizzard, Fancy Bear] APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U. S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including closeaccess operations) conducted between 2014 and 2018 against the World AntiDoping Agency (WADA), the US AntiDoping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.Volt TyphoonVolt Typhoon is a People's Republic of China (PRC) statesponsored actor that has been active since at least 2021 primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as prepositioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, livingofftheland (LOTL) binaries, hands on keyboard activities, and stolen credentials.FIREANTMustang Panda is a Chinabased cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and nongovernmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.MantisAPTC23 is a threat group that has been active since at least 2014. APTC23 has primarily focused its operations on the Middle East, including Israeli military assets. APTC23 has developed mobile spyware targeting Android and iOS devices since 2017.