Security Briefing | June 12, 2026 - Oracle PeopleSoft Zero-Day Exploited, CISA Orders Emergency Ivanti Patching, Europol Dismantles Crypto-Laundering Network
A critical Oracle PeopleSoft zero-day (CVE-2026-35273) has been actively exploited by the ShinyHunters extortion group to breach universities and enterprise systems. Meanwhile, CISA has issued an emergency directive requiring federal agencies to patch an actively exploited Ivanti Sentry vulnerability within three days. In a significant law enforcement victory, Europol has dismantled the AudiA6 cryptocurrency laundering service, cutting off a major financial channel used by ransomware gangs and cybercriminals.
By EACA Summit Content Team

1. ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
A critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft Suite, tracked as CVE-2026-35273, has been actively exploited by the ShinyHunters extortion group. Security researchers at Google's Mandiant attributed the attacks to threat actor UNC6240, which leveraged the vulnerability to steal sensitive data from enterprise environments, particularly universities. Oracle released mitigations on June 10, 2026, after the flaw had already been exploited as a zero-day.
Verified Facts
- CVE-2026-35273 is a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft Suite
- ShinyHunters (UNC6240) exploited the flaw between May 27 and June 9, 2026
- The attacks primarily targeted universities and enterprise systems
- Oracle released mitigations on June 10, 2026
- Google's Mandiant confirmed active exploitation in the wild
Evidence
- CVE-2026-35273
- Oracle June 2026 Critical Patch Update
- Mandiant and Google Threat Analysis Group attribution
Impact
Organizations running Oracle PeopleSoft should immediately apply Oracle's mitigations and review systems for signs of compromise. Institutions in the education sector may face heightened risk of data theft, extortion, and unauthorized access to sensitive records.
Confidence Level: High
The Hacker News | BleepingComputer | SecurityWeek
2. CISA Orders Federal Agencies to Patch Actively Exploited Ivanti Sentry Flaw
CISA has issued Binding Operational Directive (BOD) 26-04 requiring federal agencies to patch a critical Ivanti Sentry vulnerability within three days. The flaw is an operating system command injection vulnerability that can allow attackers to execute arbitrary code with root privileges. Security researchers have already observed exploitation attempts targeting honeypot systems, indicating that threat actors are actively pursuing vulnerable deployments.
Verified Facts
- CISA issued Binding Operational Directive 26-04
- The directive requires patching of an actively exploited Ivanti Sentry vulnerability within three days
- The flaw is a critical OS command injection vulnerability
- Successful exploitation can lead to arbitrary code execution with root privileges
- Exploitation attempts have been observed in honeypot environments
Evidence
- CISA Binding Operational Directive 26-04
- Ivanti security advisory
- Honeypot exploitation observations
Impact
Federal agencies and private-sector organizations using Ivanti Sentry should prioritize patching immediately. Failure to remediate the vulnerability could result in complete system compromise, unauthorized access, and potential lateral movement within enterprise environments.
Confidence Level: High
BleepingComputer | SecurityWeek
3. Europol Disrupts AudiA6 Crypto-Laundering Service Used by Ransomware Gangs

Europol and international law enforcement partners have dismantled AudiA6, a cryptocurrency laundering service widely used by ransomware operators and cybercriminal groups. Authorities report that the platform processed more than €336 million (approximately $389 million) in illicit cryptocurrency transactions, helping threat actors convert criminal proceeds into usable funds. The takedown removes a significant financial infrastructure component from the cybercrime ecosystem.
Verified Facts
- AudiA6 was a cryptocurrency laundering service used by ransomware gangs and cybercriminals
- The service laundered more than €336 million (~$389 million)
- Europol coordinated the disruption operation
- The platform served as a financial channel for criminal proceeds
Evidence
- Europol official statement issued June 11, 2026
- Law enforcement operation reports
Impact
The dismantling of AudiA6 disrupts a major revenue pipeline for ransomware groups and other cybercriminal organizations. While threat actors may seek alternative laundering services, the operation demonstrates increasing international cooperation against cybercrime infrastructure and financial networks.
Confidence Level: High
Sources
The Hacker News | BleepingComputer
All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.



