Skip to content

Topic

Data-theft extortion

Extortion in which leverage comes from threatening to publish stolen sensitive data rather than from encrypting or denying access to files.

Current stories

security8 publishers

ShinyHunters slips past PeopleSoft firewall rules by encoding one character

ShinyHunters is again mass-exploiting Oracle PeopleSoft flaw CVE-2026-35273, defeating firewall rules by URL-encoding a single character. Anyone who filtered the endpoint instead of applying Oracle's June 10 patch should assume exposure.

Perspective Coverage

8 publishers
Builder
Builder 25%
Operator
Operator 58%
Investor
Investor 17%

Reality

Evidence78
Adoption
Insufficient
Hype gap+8
Incentives58
Confidence74
security8 publishers

A Windchill RCE chain that never encrypts anything, and the June hunt window it opens

Suspected Cl0p operators chain a FlexPLM WSDL disclosure to CVE-2026-12569 for unauthenticated code execution. No encryption stage means ransomware-tuned detections stay silent.

Perspective Coverage

8 publishers
Builder
Builder 25%
Operator
Operator 57%
Investor
Investor 18%

Reality

Evidence68
Adoption55
Hype gap−10
Incentives60
Confidence62
product4 publishers

ShinyHunters reportedly pivoted from a recruiting server to FBI agent records

The FBI says it is investigating unauthorized activity affecting FBIjobs.gov. 404 Media reports the intruders came in through an Oracle PeopleSoft applicant server and then reached a government cloud holding agent data.

Perspective Coverage

4 publishers
Builder
Builder 19%
Operator
Operator 69%
Investor
Investor 12%

Reality

Evidence45
Adoption
Insufficient
Hype gap+35
Incentives75
Confidence60