EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJUNE 12, 20263 min read

Security Briefing | June 12, 2026 - Oracle PeopleSoft Zero-Day Exploited, CISA Orders Emergency Ivanti Patching, Europol Dismantles Crypto-Laundering Network

A critical Oracle PeopleSoft zero-day (CVE-2026-35273) has been actively exploited by the ShinyHunters extortion group to breach universities and enterprise systems. Meanwhile, CISA has issued an emergency directive requiring federal agencies to patch an actively exploited Ivanti Sentry vulnerability within three days. In a significant law enforcement victory, Europol has dismantled the AudiA6 cryptocurrency laundering service, cutting off a major financial channel used by ransomware gangs and cybercriminals.

By EACA Summit Content Team

Security Briefing | June 12, 2026 - Oracle PeopleSoft Zero-Day Exploited, CISA Orders Emergency Ivanti Patching, Europol Dismantles Crypto-Laundering Network

1. ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

A critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft Suite, tracked as CVE-2026-35273, has been actively exploited by the ShinyHunters extortion group. Security researchers at Google's Mandiant attributed the attacks to threat actor UNC6240, which leveraged the vulnerability to steal sensitive data from enterprise environments, particularly universities. Oracle released mitigations on June 10, 2026, after the flaw had already been exploited as a zero-day.

Verified Facts

  • CVE-2026-35273 is a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft Suite
  • ShinyHunters (UNC6240) exploited the flaw between May 27 and June 9, 2026
  • The attacks primarily targeted universities and enterprise systems
  • Oracle released mitigations on June 10, 2026
  • Google's Mandiant confirmed active exploitation in the wild

Evidence

  • CVE-2026-35273
  • Oracle June 2026 Critical Patch Update
  • Mandiant and Google Threat Analysis Group attribution

Impact
Organizations running Oracle PeopleSoft should immediately apply Oracle's mitigations and review systems for signs of compromise. Institutions in the education sector may face heightened risk of data theft, extortion, and unauthorized access to sensitive records.

Confidence Level: High

The Hacker News | BleepingComputer | SecurityWeek

2. CISA Orders Federal Agencies to Patch Actively Exploited Ivanti Sentry Flaw

CISA has issued Binding Operational Directive (BOD) 26-04 requiring federal agencies to patch a critical Ivanti Sentry vulnerability within three days. The flaw is an operating system command injection vulnerability that can allow attackers to execute arbitrary code with root privileges. Security researchers have already observed exploitation attempts targeting honeypot systems, indicating that threat actors are actively pursuing vulnerable deployments.

Verified Facts

  • CISA issued Binding Operational Directive 26-04
  • The directive requires patching of an actively exploited Ivanti Sentry vulnerability within three days
  • The flaw is a critical OS command injection vulnerability
  • Successful exploitation can lead to arbitrary code execution with root privileges
  • Exploitation attempts have been observed in honeypot environments

Evidence

  • CISA Binding Operational Directive 26-04
  • Ivanti security advisory
  • Honeypot exploitation observations

Impact
Federal agencies and private-sector organizations using Ivanti Sentry should prioritize patching immediately. Failure to remediate the vulnerability could result in complete system compromise, unauthorized access, and potential lateral movement within enterprise environments.

Confidence Level: High

BleepingComputer | SecurityWeek

3. Europol Disrupts AudiA6 Crypto-Laundering Service Used by Ransomware Gangs

Europol investigators conducting a cybercrime operation targeting cryptocurrency laundering networks.

Europol and international law enforcement partners have dismantled AudiA6, a cryptocurrency laundering service widely used by ransomware operators and cybercriminal groups. Authorities report that the platform processed more than €336 million (approximately $389 million) in illicit cryptocurrency transactions, helping threat actors convert criminal proceeds into usable funds. The takedown removes a significant financial infrastructure component from the cybercrime ecosystem.

Verified Facts

  • AudiA6 was a cryptocurrency laundering service used by ransomware gangs and cybercriminals
  • The service laundered more than €336 million (~$389 million)
  • Europol coordinated the disruption operation
  • The platform served as a financial channel for criminal proceeds

Evidence

  • Europol official statement issued June 11, 2026
  • Law enforcement operation reports

Impact
The dismantling of AudiA6 disrupts a major revenue pipeline for ransomware groups and other cybercriminal organizations. While threat actors may seek alternative laundering services, the operation demonstrates increasing international cooperation against cybercrime infrastructure and financial networks.

Confidence Level: High

Sources
The Hacker News | BleepingComputer

All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings