Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Chinese hackers infiltrated Microsoft 365 environments, maintaining access for 18 months before detection. The attack exploited vulnerabilities to harvest sensitive data from various organizations. Simultaneously, a new vulnerability in Oracle PeopleSoft (CVE-2026-35273) was disclosed, with active e...
A pre-authentication remote code execution (RCE) vulnerability, CVE-2026-35273, was discovered in Oracle PeopleSoft PeopleTools, affecting versions 8.61 and 8.62. The vulnerability allows unauthenticated attackers to execute code within the application server's Java virtual machine (JVM) by exploiti...
A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft has been exploited by the ShinyHunters group, leading to breaches of over 100 organizations, primarily in the education sector. The vulnerability allows unauthenticated remote code execution, enabling attackers to compromise sys...
On August 19, 2026, U.S. agencies issued a joint advisory confirming that threat actors are using AI-generated exploitation scripts to target Siemens S7 Series PLCs across critical infrastructure sectors, including water, energy, and manufacturing. The advisory, co-signed by the NSA, CISA, FBI, DOE,...