Home
Elezar
Sol Threat Intelligence

June 2026
Higher Education
Regional Sector Brief

Download PDF
1 Jun to 30 Jun 20263 regions4 pages per regionPrepared by Kaartheeswaran Ravichandran
A futuristic university knowledge citadel under a digital breach
Americas
Executive Summary
Higher education was the primary victim concentration in the PeopleSoft campaign

Americas higher education had the strongest sector-region evidence in the source set. More than 100 organizations were targeted through CVE-2026-35273 and 68 percent were reported as U.S. higher education institutions. The campaign operated as a zero-day from 27 May through 9 June, with victim data published on 9 June and Oracle issuing its advisory on 10 June. This was a systematic mass-exploitation event against a shared university ERP platform, not an isolated breach.

Key Insights
1
About 68 percent of more than 100 targets were U.S. higher education institutions, making American universities the principal victim concentration.
2
PeopleSoft Campus Solutions, HCM and Financials created a common attack surface across universities and colleges.
3
ShinyHunters used a custom fan-out script to spray SSH credentials and move across internal PeopleSoft nodes.
4
Canvas, Okta, Microsoft 365 and Salesforce formed parallel supply chain and identity attack surfaces.
5
AI vishing targeted helpdesk processes and real-time MFA interception through malicious connected-app approvals.
6
The United States also carried the highest ransomware victim share globally across June, increasing the secondary opportunistic threat to universities.
Attack chains, vulnerabilities and indicators
CVEProductCVSSJune context
CVE-2026-35273Oracle PeopleSoft PeopleTools 8.61 and 8.629.8Zero-day; about 68 percent of targets were U.S. higher education
CVE-2026-20253Splunk Enterprise9.8Risk to university SIEM infrastructure
CVE-2026-48907Joomla Widget Factory9.8Risk to university web portals
CVE-2021-44228Apache Log4j10.0Actively exploited by DragonForce in June reporting
CVE-2024-57726, 57727, 57728SimpleHelp RMMHighRelevant to outsourced university IT and MSP access
Attack Chain 1: PeopleSoft zero-day to extortion
Attack PathELEZAR
01
Internet scanning for /PSEMHUB/hub and /PSIGW/HttpListeningConnector
T1595
02
Crafted unauthenticated HTTP POST exploiting CVE-2026-35273
T1190
03
JSP webshell or XMLDecoder persistence
T1505.003
04
MeshCentral agent deployment
T1219
05
Internal discovery and SSH credential spraying
T1082 · T1018 · T1110.001
06
zstd data compression
T1560.001
07
Outbound SSH exfiltration to 176[.]120[.]22[.]24
T1048
08
Data publication and extortion
T1657
Source reports: ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit; Oracle PeopleSoft zero-day analyses
Attack Chain 2: AI vishing to cloud data theft
Attack PathELEZAR
01
AI-assisted inbound helpdesk call
T1566
02
Caller ID spoofing and account verification pretext
03
Victim directed to cloned SSO page
04
Malicious connected app approved or MFA code captured
T1111
05
Okta, Microsoft 365, Salesforce or Canvas access
T1213
06
Bulk SharePoint, OneDrive or CRM collection
T1119
07
Mail and security alert deletion
T1070
08
Extortion or resale of stolen data
T1657

Selected high-value indicators

TypeIndicatorAssociation
IP142[.]11[.]200[.]186 through 142[.]11[.]200[.]190ShinyHunters staging infrastructure
IP176[.]120[.]22[.]24Data leak site mirror and exfiltration destination
Domainazurenetfiles[.]netMeshCentral C2 masquerading as Azure infrastructure
URLwss://azurenetfiles[.]net:443/agent.ashxMeshCentral WebSocket C2
Domainbless-invite[.]comSSO and invitation phishing lure
Filemeshagent64-azure-ops.exe, meshagent32-azure-ops.exe, meshagent64-v2.exeCustomized MeshCentral agents
Path/PSEMHUB/hub and /PSIGW/HttpListeningConnectorPeopleSoft exploitation endpoints
FileREADME-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXTExtortion marker
SHA2562ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35MeshCentral agent sample
Prioritized defensive guidance

Scoped to the typical higher education environment: PeopleSoft, Canvas or other LMS platforms, federated SSO, Microsoft 365, open research networks, decentralized IT and high staff and student turnover.

Immediate: act within 72 hours
1. Assume possible PeopleSoft compromise until cleared
Check every externally exposed PeopleTools 8.61 or 8.62 environment used between 27 May and 9 June. Preserve evidence and hunt for the documented persistence, C2 and exfiltration artifacts.
2. Remove PSEMHUB and PSIGW from the internet
Place management endpoints behind VPN or internal network controls.
3. Patch and deploy the full IOC set
Apply Oracle's fix after evidence preservation and push domain, IP and hash indicators to EDR, SIEM, proxy and firewall tooling.
Urgent: act within 1 to 2 weeks
4. Harden helpdesk and account-recovery workflows
Require callback verification and never approve connected apps or MFA changes from unsolicited calls.
5. Rotate Canvas, Salesforce and SSO integrations
Revoke dormant grants, verify vendor scope and isolate CI or administrative credentials from SaaS compromise paths.
6. Enforce phishing-resistant MFA
Prioritize FIDO2 or WebAuthn for PeopleSoft, registrar, finance, HR and research administrators.
7. Address insider recruitment
Deploy UBA for bulk downloads, automate offboarding and monitor high-risk changes involving VPN, Git and SSO.
Investigate and tune detections
8. Build a FERPA-focused breach playbook
Pre-approve evidence preservation, legal review, regulator coordination and affected-person communication for student data exposure.
9. Detect QEMU-based EDR evasion
Alert on qemu-system executables, ACOW2 or QCOW2 files in ProgramData and the WindowsSensor15 scheduled task.
10. Add PeopleSoft, SaaS and helpdesk correlation rules
Correlate inbound support calls, connected-app approvals, bulk cloud downloads and new authentication methods within short time windows.
EMEA
Executive Summary
A named university breach confirms direct sector impact

EMEA higher education experienced the clearest named victim evidence in the source set. The University of Nottingham was compromised through ShinyHunters exploitation of CVE-2026-35273 in Oracle PeopleSoft, with about 455,000 unique email addresses and personal records, including passport data, published on 9 June 2026. The global campaign affected more than 100 organizations and 68 percent were higher education institutions. This confirms that PeopleSoft exposure was not theoretical for European universities.

Key Insights
1
The University of Nottingham was the only named EMEA higher education victim in the source reports.
2
Data publication preceded Oracle's advisory by one day, leaving affected institutions without official patch guidance before disclosure.
3
CVE-2026-35273 required no credentials or user interaction and targeted PeopleTools 8.61 and 8.62.
4
ShinyHunters' SaaS domino-effect model also affected Canvas-related ecosystems and cloud integrations used across universities.
5
AI vishing and insider recruitment created identity risk across Okta, Microsoft SSO, Citrix VPN and Git environments.
6
GDPR pressure increased extortion risk, both for confirmed data theft and for opportunistic ransomware operators active across EMEA.
Attack chains, vulnerabilities and indicators
CVEProductCVSSJune context
CVE-2026-35273Oracle PeopleSoft PeopleTools 8.61 and 8.629.8Actively exploited; University of Nottingham confirmed victim
CVE-2026-20253Splunk Enterprise9.8Risk to university SIEM and logging systems
CVE-2026-48907Joomla Widget Factory9.8Risk to public-facing university sites
CVE-2023-28252Windows CLFS driver7.8Actively used by Brain Cipher
CVE-2026-0257Palo Alto PAN-OS9.1Network perimeter authentication bypass risk
Attack Chain 1: PeopleSoft zero-day to extortion
Attack PathELEZAR
01
Internet scanning for /PSEMHUB/hub and /PSIGW/HttpListeningConnector
T1595
02
Crafted unauthenticated HTTP POST exploiting CVE-2026-35273
T1190
03
JSP webshell or XMLDecoder persistence
T1505.003
04
MeshCentral agent deployment
T1219
05
Internal discovery and SSH credential spraying
T1082 · T1018 · T1110.001
06
zstd data compression
T1560.001
07
Outbound SSH exfiltration to 176[.]120[.]22[.]24
T1048
08
Data publication and extortion
T1657
Source reports: ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit; Oracle PeopleSoft zero-day analyses
Attack Chain 2: AI vishing to cloud data theft
Attack PathELEZAR
01
AI-assisted inbound helpdesk call
T1566
02
Caller ID spoofing and account verification pretext
03
Victim directed to cloned SSO page
04
Malicious connected app approved or MFA code captured
T1111
05
Okta, Microsoft 365, Salesforce or Canvas access
T1213
06
Bulk SharePoint, OneDrive or CRM collection
T1119
07
Mail and security alert deletion
T1070
08
Extortion or resale of stolen data
T1657

Selected high-value indicators

TypeIndicatorAssociation
IP142[.]11[.]200[.]186 through 142[.]11[.]200[.]190ShinyHunters staging infrastructure
IP176[.]120[.]22[.]24Data leak site mirror and exfiltration destination
Domainazurenetfiles[.]netMeshCentral C2 masquerading as Azure infrastructure
URLwss://azurenetfiles[.]net:443/agent.ashxMeshCentral WebSocket C2
Domainbless-invite[.]comSSO and invitation phishing lure
Filemeshagent64-azure-ops.exe, meshagent32-azure-ops.exe, meshagent64-v2.exeCustomized MeshCentral agents
Path/PSEMHUB/hub and /PSIGW/HttpListeningConnectorPeopleSoft exploitation endpoints
FileREADME-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXTExtortion marker
SHA2562ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35MeshCentral agent sample
Prioritized defensive guidance

Scoped to the typical higher education environment: PeopleSoft, Canvas or other LMS platforms, federated SSO, Microsoft 365, open research networks, decentralized IT and high staff and student turnover.

Immediate: act within 72 hours
1. Investigate and patch PeopleSoft immediately
Preserve evidence while checking for JSP webshells, XMLDecoder persistence, MeshCentral agents, zstd staging, sshpass and outbound SSH. Patch without delaying containment.
2. Restrict PSEMHUB and PSIGW to internal access
Remove public exposure and require VPN or management-network access.
3. Block known infrastructure and review historic logs
Hunt for azurenetfiles[.]net, the five staging IPs and 176[.]120[.]22[.]24 across the prior 60 to 90 days.
Urgent: act within 1 to 2 weeks
4. Rework helpdesk identity verification
Do not approve connected apps, MFA resets or account recovery from inbound calls without callback and ticket verification.
5. Rotate Canvas and OAuth credentials
Verify breach scope, rotate Canvas API tokens and remove dormant SaaS grants.
6. Enforce phishing-resistant MFA
Use FIDO2 or WebAuthn for administrative, registry, HR, finance and research-data roles.
7. Prepare GDPR and UK GDPR response playbooks
Pre-approve supervisory authority and affected-person notification workflows for PeopleSoft data exposure.
Investigate and tune detections
8. Add PeopleSoft-specific SIEM rules
Alert on external PSEMHUB access, WebLogic child shells, JSP creation, sshpass and unusual zstd operations.
9. Prepare for GDPR-aware ransomware extortion
Create a pre-approved response for threats to notify regulators inside the 72-hour reporting window.
10. Improve offboarding and insider-risk visibility
Revoke all SSO, API and VPN credentials at departure and alert on bulk downloads by users with changing roles.
APAC
Executive Summary
PeopleSoft zero-day exposure defines the June threat picture

APAC higher education faced a defining June 2026 threat through ShinyHunters exploitation of CVE-2026-35273 in Oracle PeopleSoft PeopleTools. The campaign operated from 27 May to 9 June before Oracle published its advisory on 10 June. More than 100 organizations were notified globally and 68 percent were higher education institutions. The only named university victim in the source set was the University of Nottingham, so APAC risk is assessed from the campaign's global scanning model, ShinyHunters' documented targeting history in Australia, Japan and India, and the broad use of PeopleSoft across the region.

Key Insights
1
CVE-2026-35273, CVSS 9.8, enabled unauthenticated remote code execution against PeopleTools 8.61 and 8.62 through exposed PSEMHUB and PSIGW endpoints.
2
ShinyHunters, tracked as UNC6240, used MeshCentral agents, SSH credential spraying, zstd compression and outbound SSH exfiltration after exploitation.
3
Sixty-eight percent of more than 100 targeted organizations were higher education institutions, making this the most consequential sector campaign in the source set.
4
Canvas LMS compromise and OAuth abuse reinforced a SaaS domino-effect model in which one upstream breach can affect many universities.
5
AI-powered vishing using Bland AI and Vapi targeted helpdesk workflows, Okta or Microsoft SSO approvals and real-time MFA interception.
6
No named APAC university ransomware victim was confirmed in the source reports for June, so ransomware is treated as a secondary opportunistic risk rather than a confirmed regional incident trend.
Attack chains, vulnerabilities and indicators
CVEProductCVSSJune context
CVE-2026-35273Oracle PeopleSoft PeopleTools 8.61 and 8.629.8Zero-day RCE actively exploited against higher education
CVE-2026-20253Splunk Enterprise9.8Risk to university SIEM infrastructure
CVE-2026-48907Joomla Widget Factory9.8Risk to public-facing university web portals
CVE-2024-6387OpenSSH RegreSSHionCriticalRelevant to university Linux and SSH infrastructure
Attack Chain 1: PeopleSoft zero-day to extortion
Attack PathELEZAR
01
Internet scanning for /PSEMHUB/hub and /PSIGW/HttpListeningConnector
T1595
02
Crafted unauthenticated HTTP POST exploiting CVE-2026-35273
T1190
03
JSP webshell or XMLDecoder persistence
T1505.003
04
MeshCentral agent deployment
T1219
05
Internal discovery and SSH credential spraying
T1082 · T1018 · T1110.001
06
zstd data compression
T1560.001
07
Outbound SSH exfiltration to 176[.]120[.]22[.]24
T1048
08
Data publication and extortion
T1657
Source reports: ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit; Oracle PeopleSoft zero-day analyses
Attack Chain 2: AI vishing to cloud data theft
Attack PathELEZAR
01
AI-assisted inbound helpdesk call
T1566
02
Caller ID spoofing and account verification pretext
03
Victim directed to cloned SSO page
04
Malicious connected app approved or MFA code captured
T1111
05
Okta, Microsoft 365, Salesforce or Canvas access
T1213
06
Bulk SharePoint, OneDrive or CRM collection
T1119
07
Mail and security alert deletion
T1070
08
Extortion or resale of stolen data
T1657

Selected high-value indicators

TypeIndicatorAssociation
IP142[.]11[.]200[.]186 through 142[.]11[.]200[.]190ShinyHunters staging infrastructure
IP176[.]120[.]22[.]24Data leak site mirror and exfiltration destination
Domainazurenetfiles[.]netMeshCentral C2 masquerading as Azure infrastructure
URLwss://azurenetfiles[.]net:443/agent.ashxMeshCentral WebSocket C2
Domainbless-invite[.]comSSO and invitation phishing lure
Filemeshagent64-azure-ops.exe, meshagent32-azure-ops.exe, meshagent64-v2.exeCustomized MeshCentral agents
Path/PSEMHUB/hub and /PSIGW/HttpListeningConnectorPeopleSoft exploitation endpoints
FileREADME-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXTExtortion marker
SHA2562ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35MeshCentral agent sample
Prioritized defensive guidance

Scoped to the typical higher education environment: PeopleSoft, Canvas or other LMS platforms, federated SSO, Microsoft 365, open research networks, decentralized IT and high staff and student turnover.

Immediate: act within 72 hours
1. Forensically assess all PeopleTools 8.61 and 8.62 systems
Treat any externally exposed PSEMHUB or PSIGW deployment present between 27 May and 9 June as potentially compromised. Hunt for unexpected JSP files, modified XML under envmetadata/data/environment, MeshCentral agents, sshpass use, zstd staging and outbound SSH.
2. Remove PSEMHUB and PSIGW from public exposure
Restrict /PSEMHUB/hub and /PSIGW/HttpListeningConnector to trusted internal ranges or VPN access only.
3. Block and retrospectively hunt ShinyHunters infrastructure
Block azurenetfiles[.]net, 142[.]11[.]200[.]186 through 142[.]11[.]200[.]190 and 176[.]120[.]22[.]24. Review at least 60 days of proxy, firewall and endpoint telemetry.
Urgent: act within 1 to 2 weeks
4. Harden university helpdesks against AI vishing
Require callback verification and ticket-bound out-of-band codes for MFA resets, connected-app approvals and account recovery.
5. Audit OAuth and SaaS integrations
Revoke dormant or unexplained tokens across Canvas, Okta, Microsoft 365 and Salesforce. Verify vendor breach scope and rotate exposed API credentials.
6. Move privileged users to phishing-resistant MFA
Prioritize FIDO2, WebAuthn or passkeys for PeopleSoft administrators, finance, HR, registry and research data custodians.
7. Address insider recruitment risk
Use UBA for bulk downloads, tighten offboarding and monitor high-risk access changes involving SSO, VPN and Git platforms.
Investigate and tune detections
8. Deploy PeopleSoft-specific detections
Alert on external POSTs to PSEMHUB, WebLogic spawning shell tools, JSP creation in application directories, sshpass on application hosts and outbound SSH to unapproved destinations.
9. Reduce USB malware exposure
Disable or tightly control USB storage on shared lab systems and detect LNK execution from removable media.
10. Establish vendor breach notification SLAs
Require rapid disclosure, OAuth rotation support and annual token hygiene reviews from core SaaS vendors.