Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (12 June 2026)
Published: Loading…
At a Glance
- UNC6240 ShinyHunters exploited CVE-2026-35273 in Oracle PeopleSoft Environment Management, enabling unauthenticated remote code execution across 300 instances affecting over 100 organisations globally.
- The University of Nottingham confirmed a cyber incident following ShinyHunters data theft, exposing approximately 455,000 student and alumni email addresses alongside academic and financial records.
- Oracle released an out-of-band security alert for PeopleSoft CVE-2026-35273 while investigations continued into limited exploitation and mitigations for enterprise deployments.
- Europol dismantled the AudiA6 cryptocurrency laundering service linked to ransomware groups, freezing funds and seizing infrastructure used to process illicit proceeds across multiple jurisdictions.
- Researchers demonstrated the FROST attack, using OPFS-based SSD timing side channels to infer application and website activity from browser-driven storage contention patterns.
- Kyushu Electric Power disclosed a missing external storage device containing customer data for up to 10.9 million accounts after a physical security lapse in a server room.
Summary
The ShinyHunters campaign centred on Oracle PeopleSoft CVE-2026-35273, with exploitation enabling unauthenticated remote code execution across enterprise environments. Over 100 organisations were impacted, with activity concentrated in higher education sectors and multi-instance deployments. Oracle issued an out-of-band advisory as mitigation measures were deployed during active exploitation.
The University of Nottingham confirmed a cyber incident linked to ShinyHunters data theft activity affecting student and alumni records. Approximately 455,000 email addresses were exposed alongside personal, academic, and financial information. The breach forms part of wider targeting of education-sector systems using enterprise application vulnerabilities.
Europol coordinated the dismantling of the AudiA6 cryptocurrency laundering infrastructure used by ransomware groups. The operation disrupted financial flows totalling hundreds of millions of euros and included domain seizures and cryptocurrency freezes. Investigators identified extensive mule account networks supporting laundering operations.
Security researchers disclosed the FROST side-channel attack, leveraging SSD access timing through OPFS browser functionality. The method enables inference of application and website activity using storage contention patterns measured at high resolution. Machine learning models were used to classify behavioural activity from latency signals.
Physical and operational security failures were reported in the Kyushu Electric Power incident involving a missing storage device. The drive contained customer data for up to 10.9 million accounts including personal identifiers and utility usage records. Authorities were notified following internal investigation into access to secure server room infrastructure.
Highlights of the Day
ShinyHunters Exploit Oracle PeopleSoft Zero-Day in Education Campaign
UNC6240 (ShinyHunters) exploited CVE-2026-35273, a CVSS 9.8 remote code execution zero-day in Oracle PeopleSoft Environment Management between 27 May and 9 June 2026. Staging infrastructure used MeshCentral 1.1.59, Python SimpleHTTP servers, and Azure-masquerading agents hosted across sequential IPs 142[.]11[.]200[.]186–190 with azurenetfiles[.]net C2 domain infrastructure. GTIG notified over 100 organisations, 68 percent higher education in United States, after compromises linked to ShinyHunters Data Leak Site publication on 9 June 2026.
ShinyHunters Leak Exposes University of Nottingham Student Records
The University of Nottingham confirmed a cyber incident following data published by ShinyHunters, who claimed to have accessed internal systems and extracted significant student records. Analysis indicates approximately 455,000 unique email addresses were exposed alongside names, passports, contact details, and academic and financial information across students and alumni. The university stated that both current students and alumni are affected, and it is coordinating with Action Fraud, the Information Commissioner’s Office, and regulatory bodies.
Oracle Issues Emergency Fix for PeopleSoft Zero-Day Exploitation
Oracle released an out-of-band security alert addressing CVE-2026-35273, a critical PeopleSoft vulnerability affecting Enterprise PeopleTools versions 8.61 and 8.62 that can enable unauthenticated remote code execution. Reports indicate exploitation attempts targeting approximately 300 PeopleSoft instances across more than 100 organisations, with attackers allegedly chaining multiple vulnerabilities including zero-days to access enterprise data. The advisory follows activity attributed to ShinyHunters, with Oracle confirming mitigations are available while investigation into limited real-world exploitation remains ongoing.
APT28 Tradecraft Evolves Across Two Decades of GRU Operations
APT28 tradecraft analysis maps two decades of GRU Unit 26165 operations, detailing shifts in tooling, infrastructure, and targeting across multiple operational eras Recent phases show fragmented single-purpose malware, zero-click Outlook exploitation via CVE-2023-23397, and infrastructure shifted to compromised edge routers and SOHO devices Latest operations include Phantom Net Voxel in-memory Covenant deployments and LameHug, an LLM-driven infostealer querying cloud AI services for command execution
AI-Themed LNK Campaign Delivers AsyncRAT via Multi-Stage Loader
FortiGuard Labs observed a Windows campaign distributing AI-themed documents in compressed archives containing LNK files and hidden PDFs targeting users seeking AI resources. The infection chain uses LNK-based line extraction from disguised PDFs, staged PowerShell scripts, and AutoHotkey loaders to reflectively inject AsyncRAT into memory. Persistence is achieved through scheduled tasks, Realtek-themed services, and obfuscated scripts using multilingual variables, ultimately enabling AsyncRAT command-and-control communication and full system compromise.
Chinese Actors Target FIFA 2026 Ticket Fraud Operation
CloudSEK reported a Chinese-origin operation targeting FIFA World Cup 2026 ticket buyers with cloned sites and MitM phishing bypassing SMS OTP via tbpay.uk infrastructure. Infrastructure included typosquatted FIFA domains, multi-tenant reseller panels, tawk.to live chat, and card-skimming backend activity linked to Chinese IP 222[.]167[.]244[.]34 with Simplified Chinese interfaces. Data centre logs showed full victim journey tracking, including card CVV capture and OTP verification stages, with traffic from Facebook and Instagram in-app browsers.
GlobalProtect Authentication Bypass Exploited via CVE-2026-0257 Campaign
Arctic Wolf reported exploitation of CVE-2026-0257 affecting Palo Alto Networks PAN-OS GlobalProtect, enabling authentication bypass via forged cookies in late May–June 2026 campaigns. Suspicious activity originated from VPS hosting infrastructure, with cookie decryption failures followed by successful logins and IPsec VPN tunnel establishment on affected gateways. Sustained access in a subset of intrusions enabled Impacket-based SMB reconnaissance, NTLM authentication attempts, and limited internal network discovery following VPN session establishment.
Europol Dismantles AudiA6 Crypto Laundering Network
Europol-led operation dismantled AudiA6, a crypto laundering service linked to ransomware groups, responsible for processing over EUR 336 million between 2022 and 2025. Authorities arrested two suspects in Georgia, seized more than 30 servers and 25 domains, and froze EUR 692,000 in cryptocurrency assets during coordinated action. Investigators linked the operation to over 15 global cases and identified 6,000 KYC mule records connected to ransomware proceeds and Dark2Web forum infrastructure.
FROST Attack Uses SSD Timing to Track Browser Activity
Researchers at Graz University of Technology demonstrated FROST, a browser-based side-channel attack that leverages Origin Private File System (OPFS) timing variations to infer user activity from SSD access delays. The technique measures contention on storage I/O operations to fingerprint application launches and website visits, achieving up to 661 bits per second covert channel throughput on Linux and 891 bits per second on macOS. Experimental results showed website identification accuracy of 88.95% and application detection accuracy of 95.83% using machine learning models trained on SSD latency patterns.
Kyushu Electric Reports Missing Drive Exposing 10.9 Million Records
Kyushu Electric Power disclosed the loss of an external storage device containing data belonging to up to 10.9 million customers after it went missing from a locked server room cabinet in late May 2026. The compromised drive held customer names, addresses, electricity usage data, telephone numbers, and retail electricity provider details, though the company confirmed no financial or card information was included. Internal checks identified 57 staff with access to the server room, and the company has reported the incident to Japanese authorities and the Personal Information Protection Commission.
Daily Coverage