# Threat Intel Brief — June 12, 2026
TL;DR
- Oracle PeopleSoft zero-day (CVE-2026-35273) actively exploited by ShinyHunters for unauthenticated RCE; patch immediately.
- Ivanti Sentry maximum-severity RCE under active exploitation; root-level compromise possible on internet-exposed gateways.
- Microsoft June Patch Tuesday addresses 206 vulnerabilities including three zero-days (YellowKey, GreenPlasma, MiniPlasma) enabling SYSTEM access and BitLocker bypass.
- China-linked JDY botnet expands reconnaissance operations against U.S. military networks with 1,500+ compromised IoT devices.
- CISA mandates 3-day patching for exploited critical vulnerabilities across federal agencies via Binding Operational Directive 26-04.
Critical Threats
Oracle PeopleSoft Zero-Day Exploitation (CVE-2026-35273)
What happened: ShinyHunters (tracked by Mandiant as UNC6240) exploited an unauthenticated remote code execution vulnerability in Oracle PeopleSoft Suite between May 27 and June 9, 2026, before Oracle published patches on June 10. The threat actor successfully breached enterprise systems and universities, exfiltrated data, and issued extortion demands. The group claims over 100 compromised organizations.
Impact: Any internet-facing PeopleSoft instance was vulnerable to complete system compromise without authentication. PeopleSoft deployments typically contain sensitive HR data, financial records, and student information. Organizations may have been compromised for up to two weeks before patch availability. ShinyHunters has a history of selling stolen databases on underground forums and conducting aggressive extortion campaigns.
Recommendations:
- Apply Oracle's June 10 security patch for CVE-2026-35273 to all PeopleSoft instances immediately
- Review access logs from May 27 through present for indicators of compromise
- Search for UNC6240/ShinyHunters TTPs in SIEM and EDR telemetry
- Conduct forensic analysis on PeopleSoft servers for evidence of data exfiltration
- Implement network segmentation and restrict external access until patching is complete
Ivanti Sentry Maximum-Severity RCE Under Active Exploitation
What happened: Attackers are actively exploiting a maximum-severity vulnerability in Ivanti Sentry (formerly MobileIron Sentry) that allows unauthenticated remote code execution with root privileges on internet-exposed secure mobile gateways. Ivanti released patches on June 9, but exploitation began before public disclosure.
Impact: Root-level access to Sentry gateways enables full system compromise, lateral movement into internal networks, data exfiltration, and potential supply chain attacks against mobile device management infrastructure. Organizations with internet-exposed Sentry instances face immediate breach risk. Ivanti products have been heavily targeted in recent campaigns, increasing likelihood of rapid exploitation.
Recommendations:
- Identify all internet-exposed Ivanti Sentry instances and apply patches immediately
- If immediate patching is not feasible, isolate Sentry systems from the internet or implement strict IP allowlisting
- Review Sentry system logs for anomalous authentication attempts, unexpected process execution, or outbound connections
- Conduct forensic analysis on any Sentry instance that was internet-exposed prior to patching
- Monitor for CISA alerts and Ivanti advisories for IOCs and additional guidance
Microsoft Zero-Days: YellowKey, GreenPlasma, MiniPlasma
What happened: Microsoft's June 2025 Patch Tuesday addressed 206 vulnerabilities, including three actively exploited zero-days. YellowKey and GreenPlasma enable attackers to gain SYSTEM privileges on fully patched Windows systems. MiniPlasma allows unauthorized access to BitLocker-protected drives, defeating disk encryption controls.
Impact: Attackers with initial access can escalate to SYSTEM privileges on any Windows endpoint or server, enabling full system compromise. MiniPlasma undermines BitLocker's data-at-rest protection for lost or stolen devices. High risk for ransomware deployment, data exfiltration, and persistent compromise across Windows infrastructure.
Recommendations:
- Deploy Microsoft's latest Windows security updates immediately to all endpoints and servers
- Prioritize patching for domain controllers, file servers, and systems with BitLocker-encrypted drives
- Review Windows Security and EDR logs for unusual privilege escalation attempts or unauthorized BitLocker access
- Verify BitLocker recovery key storage and access controls are properly configured and monitored
- Implement application whitelisting and restrict local administrator rights until patching is complete
Langflow Path Traversal (CVE-2026-5027) Actively Exploited
What happened: Attackers are actively exploiting CVE-2026-5027, a high-severity path traversal vulnerability in Langflow, an open-source low-code AI platform. The flaw allows unauthenticated attackers to write arbitrary files to vulnerable servers, enabling remote code execution. No patch is currently available.
Impact: Unauthenticated RCE on exposed Langflow instances enables full system compromise. Organizations running Langflow for AI workflow development face immediate risk of data breach, lateral movement, and infrastructure takeover. The lack of an available patch increases urgency for compensating controls.
Recommendations:
- Immediately isolate or disable internet-facing Langflow instances until patch is available
- Restrict Langflow access to trusted internal networks only via firewall rules or VPN
- Monitor web server and application logs for path traversal patterns (e.g., '../' sequences in requests)
- Audit Langflow deployments for indicators of compromise: unexpected files, new user accounts, or unauthorized processes
- Subscribe to Langflow security advisories and apply patch immediately upon release
Windows Server Domain Controller RCE Under Active Exploitation
What happened: Microsoft published a critical advisory on May 12, 2026, regarding an unauthenticated remote code execution vulnerability affecting Windows Server domain controllers. The vulnerability is currently being actively exploited by threat actors in the wild. CVE identifier not yet assigned.
Impact: Unauthenticated RCE on domain controllers enables full Active Directory compromise, credential theft, lateral movement, and persistent access to enterprise networks. Immediate risk to business continuity and data confidentiality. Domain controllers serve as the authentication backbone for organizational IT infrastructure.
Recommendations:
- Monitor Microsoft Security Response Center for emergency patch release and apply immediately upon availability
- Isolate domain controllers from untrusted networks; restrict access using firewall rules and network segmentation
- Enable enhanced logging on domain controllers and monitor for anomalous authentication attempts or service crashes
- Review domain controller access logs for indicators of compromise; check for unauthorized administrative account creation
- Implement compensating controls: disable unnecessary services, enforce strict RPC and SMB filtering, deploy network-based IDS/IPS
Threat Actor Activity
ShinyHunters (UNC6240) — PeopleSoft Zero-Day Campaign
ShinyHunters, a financially motivated cybercrime group tracked by Mandiant as UNC6240, exploited CVE-2026-35273 in Oracle PeopleSoft for two weeks before vendor disclosure. The group successfully breached enterprises and universities, exfiltrated data, and issued extortion demands. ShinyHunters has a history of large-scale database theft and sale on underground forums. The rapid weaponization of the zero-day demonstrates sophisticated vulnerability research capabilities.
Defensive priorities: Patch PeopleSoft immediately, hunt for UNC6240 TTPs in environments, monitor for bulk data extraction patterns, and implement network segmentation for ERP systems.
China-Linked JDY Botnet — U.S. Military Reconnaissance
The JDY botnet, previously linked to Volt Typhoon and other China-nexus state-sponsored actors, has expanded to over 1,500 compromised SOHO routers and IoT devices. The botnet operates as a centrally controlled, high-performance scanner conducting cyber reconnaissance against U.S. military networks and exposed internet services globally. The infrastructure enables large-scale target mapping, fingerprinting, and continuous intelligence collection.
Defensive priorities: Monitor for anomalous outbound scanning from IoT/SOHO devices, implement network segmentation, enforce firmware updates, analyze NetFlow logs for reconnaissance patterns, and harden devices by disabling unnecessary services.
OceanLotus (APT32) — Vietnam Infrastructure Espionage
OceanLotus, a Vietnam-aligned APT group, conducted a prolonged 20-month cyber espionage campaign against a Vietnamese infrastructure and transport construction corporation from mid-2024 to February 2026 using the SPECTRALVIPER backdoor. The group also targeted stock investors via supply chain attacks. OceanLotus demonstrates sophisticated capabilities in long-term network compromise and domestic surveillance operations.
Defensive priorities: Monitor for spearphishing with Vietnamese-language lures, detect WMI and JavaScript execution via Sysmon, implement credential protection controls, hunt for NTFS file attribute manipulation, and deploy YARA rules for SPECTRALVIPER and known OceanLotus malware families.
The Gentlemen Ransomware — Aggressive Affiliate Model
The Gentlemen ransomware operation has emerged as the second most active ransomware group by victim count, claiming 478 victims. The group operates an aggressive affiliate recruitment model offering 90% ransom splits—significantly above typical RaaS commission structures. The ransomware demonstrates worm-like spreading capabilities, enabling automated lateral movement across networked systems.
Defensive priorities: Monitor for lateral movement indicators consistent with worm propagation, implement network segmentation, deploy behavioral detection for double extortion TTPs, maintain offline immutable backups, and hunt for artifacts associated with LockBit, Qilin, and Medusa RaaS infrastructure.
Geopolitical Context
CISA Binding Operational Directive 26-04
CISA issued Binding Operational Directive 26-04 requiring Federal Civilian Executive Branch agencies to patch critical exploited vulnerabilities within three days. This policy tightening reflects growing concern over rapid weaponization of public disclosures by state-sponsored and criminal actors. The directive follows high-profile compromises including SolarWinds, Log4j, and MOVEit incidents. The measure is likely to influence cybersecurity policy among Five Eyes partners and NATO allies.
South Korea Record Data Protection Fine
South Korea's Personal Information Protection Commission fined e-commerce company Coupang a record $409 million following a breach affecting over 37 million customers. The unprecedented penalty reflects South Korea's increasingly assertive regulatory posture on data protection and may influence regional approaches in Japan, Taiwan, and Southeast Asia. The fine establishes a new benchmark for data protection enforcement in Asia-Pacific.
China-U.S. Cyber Tensions
The expansion of the China-linked JDY botnet's reconnaissance operations against U.S. military networks represents an escalation in APT activity targeting critical U.S. defense infrastructure. The activity is consistent with PRC strategic priorities to understand and potentially degrade U.S. military command, control, and logistics capabilities, particularly in Taiwan Strait contingency scenarios.
Recommended Actions
Immediate (0-24 hours)
- Patch Oracle PeopleSoft for CVE-2026-35273 on all instances; prioritize internet-facing deployments
- Patch Ivanti Sentry for maximum-severity RCE; isolate from internet if patching delayed
- Deploy Microsoft June patches addressing YellowKey, GreenPlasma, and MiniPlasma zero-days
- Isolate Langflow instances from internet until CVE-2026-5027 patch is available
- Monitor for Windows Server domain controller compromise indicators; await Microsoft emergency patch
- Review CISA KEV catalog and patch CVE-2026-20245 (Cisco Catalyst SD-WAN Manager) and CVE-2026-5027 (Langflow)
Within 24-72 hours
- Conduct forensic analysis on PeopleSoft servers for May 27-June 9 compromise indicators
- Hunt for ShinyHunters/UNC6240 TTPs in SIEM and EDR telemetry across enterprise environments
- Audit Ivanti Sentry logs for suspicious authentication attempts or unexpected administrative actions
- Review BitLocker configurations and recovery key access controls following MiniPlasma disclosure
- Patch Fortinet FortiSandbox for CVE-2026-25089 command injection vulnerability
- Assess npm v12 impact on development pipelines; test install script dependencies before upgrade
This week
- Implement CISA BOD 26-04 compliance for federal agencies; private sector should adopt similar timelines
- Deploy network segmentation for PeopleSoft, Ivanti Sentry, and other enterprise applications
- Harden IoT/SOHO devices against JDY botnet compromise; restrict management interfaces, change default credentials
- Review supply chain security for npm dependencies and open-source packages following Miasma framework leak
- Conduct threat hunting for OceanLotus TTPs in infrastructure and finance sector environments
- Patch SAP products per vendor advisories addressing critical vulnerabilities
- Address CVE-2026-8335 (Aix-DB missing authentication) if software is deployed in your environment
Watch List
- Oracle PeopleSoft — Monitor for additional ShinyHunters activity and expanded targeting
- Ivanti Sentry — Track for proof-of-concept exploit code and increased exploitation attempts
- Microsoft zero-days — Watch for adversary adoption of YellowKey, GreenPlasma, MiniPlasma exploits
- Langflow CVE-2026-5027 — Await patch release; monitor for exploitation escalation
- Windows Server domain controllers — Track Microsoft for CVE assignment and emergency patch
- JDY botnet — Monitor for expansion beyond U.S. military networks to allied infrastructure
- Veeam Backup & Replication — Await CVE assignment and technical details for critical RCE
- ServiceNow — Monitor for CVE assignment and technical details on authentication bypass
- Microsoft Defender RoguePlanet — Track for CVE assignment and patch release
- protobuf.js — Await CVE assignment and patched versions for six RCE/DoS vulnerabilities
- OpenClaw AI agent — Monitor for CVE assignment and vendor patches for prompt injection flaws
Sources
- BleepingComputer
- The Hacker News
- CERT.BE (Belgium)
- CERT-EU Advisories
- CERT.PL (Poland)
- Krebs on Security
- CISA Known Exploited Vulnerabilities Catalog
- Microsoft Security Response Center
- Oracle Critical Patch Updates
- Ivanti Security Advisories
---
*This report synthesizes open-source threat intelligence as of June 12, 2026. Organizations should validate findings against their specific environments and consult vendor advisories for authoritative technical guidance.*
