ShinyHunters is again mass-exploiting Oracle PeopleSoft flaw CVE-2026-35273, defeating firewall rules by URL-encoding a single character. Anyone who filtered the endpoint instead of applying Oracle's June 10 patch should assume exposure.
Perspective Coverage
8 publishers
- Builder
- Builder 25%
- Operator
- Operator 58%
- Investor
- Investor 17%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+8
- Incentives58
- Confidence74
Google says UNC6671 split its extortion into Redact, Pink, Helix and Falcon on shared infrastructure while still working finance, legal and med tech. It averages 1.5 new victims a day.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives45
- Confidence55
Suspected Cl0p operators chain a FlexPLM WSDL disclosure to CVE-2026-12569 for unauthenticated code execution. No encryption stage means ransomware-tuned detections stay silent.
Perspective Coverage
8 publishers
- Builder
- Builder 25%
- Operator
- Operator 57%
- Investor
- Investor 18%
Reality
- Evidence68
- Adoption55
- Hype gap−10
- Incentives60
- Confidence62
The FBI says it is investigating unauthorized activity affecting FBIjobs.gov. 404 Media reports the intruders came in through an Oracle PeopleSoft applicant server and then reached a government cloud holding agent data.
Perspective Coverage
4 publishers
- Builder
- Builder 19%
- Operator
- Operator 69%
- Investor
- Investor 12%
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+35
- Incentives75
- Confidence60
Tom Uren and James Wilson say the cybercrime ecosystem is moving to data-theft extortion. For reputation-sensitive organisations, that puts the dominant loss outside recovery planning.
Reality
- Evidence18
- Adoption
- Insufficient
- Hype gap+30
- Incentives
- Insufficient
- Confidence25