- 开始
- 2026年6月10日可信度 90%来自来源
甲骨文紧急修补遭 ShinyHunters 利用的 PeopleSoft 零日漏洞
由原文自动翻译
原标题: Oracle Issues Emergency Fix for PeopleSoft Zero-Day Hit by ShinyHunters
- 2026 年 6 月 10 日,甲骨文针对 PeopleSoft Enterprise PeopleTools 8.61 和 8.62 发布安全警报 CVE-2026-35273;该漏洞位于 Updates Environment Management 组件,无需身份验证即可远程利用,并可能导致远程代码执行,CVSS 3.1 评分为 9.8[1]。
- 甲骨文发布了缓解措施,敦促用户“立即采取行动”;PeopleSoft Enterprise Applications 客户也可能受影响,TrendAI 旗下 Zero Day Initiative 的研究人员获致谢[1][3]。
- 同日,ShinyHunters 向 BleepingComputer 证实,已从 100 多家机构的 300 个 PeopleSoft 实例中窃取数据,其中大多为教育机构;诺丁汉大学也承认发生了网络安全事件[4]。
- Mandiant 表示已通知 100 多家机构,其中大部分位于美国,68% 为高等院校,并将数据外泄与一台关联 ShinyHunters 泄露网站的服务器联系起来[3]。
- 美国网络安全和基础设施安全局(CISA)于 6 月 12 日将该漏洞列入已知被利用漏洞目录,要求联邦机构在 6 月 15 日前完成处置[2]。
参考资料 4可信度 88%
第一项始终是图钉的来源。总体可信度是各份资料对上方所用开始和结束时间支持程度的加权平均;资料每比最新的一份旧 180 天,权重减半。
- [1]90%oracle.com/security-alerts/alert-cve-2026-35273.htmloracle.com· 发布于 2026年9月24日· 开始 2026年6月10日 ✓· 占评分 30%
甲骨文 CVE-2026-35273 安全警报公告的修改历史中列有“2026-June-10 Rev 1. Initial Release”(2026 年 6 月 10 日第 1 版,首次发布)。
- [2]90%CISA Known Exploited Vulnerabilities Catalog (JSON feed)cisa.gov· 发表于 2026年9月23日· 占评分 30%
CVE-2026-35273 added 2026-06-12 with a 2026-06-15 due date under BOD 26-04, known ransomware campaign use 'Known'.[1]
- [3]85%Oracle mitigates PeopleSoft zero-day exploited in data theft attacksbleepingcomputer.com· 发表于 2026年6月11日· 占评分 20%
Ties the alert to the ShinyHunters attacks and quotes Mandiant: over 100 organizations notified, 68 percent in higher education.[1]
- [4]85%Oracle PeopleSoft servers hacked in ShinyHunters data theft attacksbleepingcomputer.com· 发表于 2026年6月10日· 占评分 20%
ShinyHunters confirmed the attacks, claiming data from 300 instances at more than 100 organizations; the University of Nottingham acknowledged a cyber incident.[1]
建议更正
有遗漏或错误吗?用你自己的话说明:能佐证此图钉的链接、不同的开始或结束日期及理由,或缺失、有误的信息。AI 会对照此图钉的来源进行核实,搜索更好的来源,并添加任何支持你说法的页面。图钉自身的来源仍然最重要。