daily cyber × ai intelligence

index

tagged

[bling-libra]

1 edition · 1 item

June 18, 2026

  • Oracle PeopleSoft CVE-2026-35273 unauthenticated RCE is under active exploitation by ShinyHunters (aka Bling Libra), with the education sector hit hardest since at least late May. Horizon3 confirmed exploitation predating disclosure, and Unit 42 corroborates the campaign against universities. watchTowr warns that "vibecoded" PoCs circulating are only the first-stage SSRF, not the full chain — treat public exploits skeptically (watchTowr). · Vulnerabilities & Exploits

in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel