Last Updated: 2026-06-12T20:05:11Z
What’s Happening
CVE-2026-35273, a CVSSv3 9.8 severity vulnerability allows “takeover” or “code execution.” No details on mechanism as yet.
https://www.oracle.com/security-alerts/alert-cve-2026-35273.html
The CVE listing shows the CWE as CWE-308, or “Missing Authentication for Critical Function.” So presumably an auth bypass or Broken Function Level Authorization on an API endpoint.
The Register reports that ShinyHunters credit this vulnerability for the breach of the University of Nottingham, along with many other organizations.
Actions
Apply available patches to PeopleTools instances ASAP.
Indicators of Compromise
Hunt for these IoCs from Palo Alto.
| Value | Type | Description |
|---|---|---|
45.135.232[.]140 |
IPv4 | C2 / infrastructure |
91.215.85[.]101 |
IPv4 | C2 / infrastructure |
108.174.202[.]99 |
IPv4 | C2 / infrastructure |
142.11.200[.]186 |
IPv4 | C2 / infrastructure |
142.11.200[.]187 |
IPv4 | C2 / infrastructure |
142.11.200[.]188 |
IPv4 | C2 / infrastructure |
142.11.200[.]189 |
IPv4 | C2 / infrastructure |
142.11.200[.]190 |
IPv4 | C2 / infrastructure |
176.120.22[.]24 |
IPv4 | C2 / infrastructure |
207.89.18[.]29 |
IPv4 | C2 / infrastructure |
azurenetfiles[.]net |
Domain | C2 / infrastructure |
bmwebhost[.]com |
Domain | C2 / infrastructure |
onlinepaymentterminal[.]com |
Domain | C2 / infrastructure |
paymentprocessterminal[.]com |
Domain | C2 / infrastructure |
techvertix[.]com |
Domain | C2 / infrastructure |
78166e8cd026f6f7fc612244e587c2565487f2635fc3d704987972ede619aef9 |
SSH Key Fingerprint | Attacker SSH key fingerprint |
9098906159e0e4c845eb918886fadc2723f2a321281b8003e471f09140321f91 |
SHA256 | Malware sample |
c7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711f |
SHA256 | Malware sample |
d65f14e5652a4330354826925dc56937334163656f24dd10f112c15bc7559de1 |
SHA256 | Malware sample |
Notes
For other reasons, Oracle stock is down 8.53% on the day.