# Threat Intel Brief — June 13, 2026

TL;DR

  • Oracle PeopleSoft zero-day (CVE-2026-35273) actively exploited by ShinyHunters/UNC6240 for data theft against enterprises and universities; patch immediately.
  • Ivanti Sentry maximum-severity RCE under active exploitation; CISA orders federal agencies to patch within 3 days under BOD 26-04.
  • Arch User Repository supply chain attack: 400+ packages compromised with Rust infostealer and eBPF rootkit targeting developer credentials.
  • China-linked Velvet Ant maintained nearly decade-long persistence via backdoored Linux PAM and OpenSSH authentication components.
  • Law enforcement wins: Conti operative pleads guilty after extradition; Europol disrupts €336M AudiA6 crypto laundering service; INTERPOL arrests Sniper Dz phishing platform admin.

---

Critical Threats

Oracle PeopleSoft Zero-Day Exploitation (CVE-2026-35273)

What happened: ShinyHunters (tracked by Google Mandiant as UNC6240) exploited an unauthenticated remote code execution vulnerability in Oracle PeopleSoft Suite between May 27 and June 9, 2026—before Oracle published its advisory on June 10. The threat actor targeted enterprise systems and universities, exfiltrating data and demanding extortion payments. CVE-2026-35273 allows attackers to execute arbitrary code on internet-facing PeopleSoft instances without authentication.

Impact: Organizations running PeopleSoft face immediate risk of data breach and extortion. PeopleSoft typically hosts sensitive HR, financial, and supply chain data across enterprise and education sectors. The two-week exploitation window prior to patch availability indicates multiple organizations may already be compromised. ShinyHunters has a documented history of large-scale data theft and sale on underground forums.

Recommendations:

  • Apply Oracle's June 10 security patch for CVE-2026-35273 to all PeopleSoft instances immediately.
  • Review PeopleSoft access logs from May 27 through June 9 for indicators of compromise, focusing on unusual authentication patterns or data access.
  • Isolate unpatched PeopleSoft systems from network until patching is complete.
  • Engage incident response if PeopleSoft was internet-accessible during the exploitation window; assume breach until proven otherwise.
  • Monitor for extortion attempts or data leak announcements from ShinyHunters on dark web forums.

---

Ivanti Sentry Maximum-Severity RCE Under Active Exploitation

What happened: Attackers are actively exploiting a maximum-severity vulnerability in Ivanti Sentry (formerly MobileIron Sentry) that allows remote code execution with root privileges on internet-exposed secure mobile gateways. CISA issued Binding Operational Directive 26-04 ordering U.S. federal agencies to patch within three days. The flaw has been recently patched but is now being targeted in active attacks.

Impact: Root-level RCE grants attackers full system compromise, enabling lateral movement into internal networks, data exfiltration, and potential supply chain attacks against mobile device management infrastructure. Organizations with internet-exposed Sentry instances face immediate risk of breach. Ivanti products have been heavily targeted in recent campaigns.

Recommendations:

  • Identify all internet-exposed Ivanti Sentry instances and apply the latest security patch immediately.
  • If patching cannot be completed within hours, isolate Ivanti Sentry systems from the internet or shut down until patched.
  • Review Sentry system logs and network traffic for indicators of compromise, focusing on unusual authentication attempts, unexpected processes, or outbound connections.
  • Conduct forensic analysis on any Sentry instance that was internet-exposed prior to patching.
  • Implement network segmentation to limit Sentry gateway access and monitor all traffic to/from these systems.

---

Arch User Repository Supply Chain Compromise

What happened: Attackers compromised over 400 packages in the Arch User Repository (AUR) by modifying build scripts to deploy a Rust-based infostealer malware that harvests developer credentials. The malware can load an eBPF rootkit when executed with root privileges to conceal its presence on infected systems. The attack targets developers and system administrators using AUR packages.

Impact: High risk of credential theft affecting developers who built compromised AUR packages. Stolen credentials may include SSH keys, API tokens, cloud credentials, and source code repository access. Systems where packages were built with root privileges may have persistent eBPF rootkit infections that evade standard detection. Potential for lateral movement and supply chain propagation if developer credentials are used to access production systems or code repositories.

Recommendations:

  • Identify all systems that installed or updated AUR packages during the compromise period using pacman logs and AUR helper histories.
  • Rotate all developer credentials on affected systems including SSH keys, GPG keys, API tokens, cloud provider credentials, and Git repository access tokens.
  • Scan affected systems for Rust-based malware artifacts and eBPF rootkit presence using tools like bpftool to list loaded eBPF programs.
  • Review outbound network connections from affected systems for data exfiltration to attacker infrastructure.
  • Rebuild affected systems from known-clean media if root-level execution occurred or if eBPF rootkit presence is confirmed.

---

Velvet Ant: Decade-Long Linux Authentication Backdoor

What happened: A China-linked threat actor tracked as Velvet Ant backdoored Linux PAM (Pluggable Authentication Modules) and OpenSSH components to maintain persistent access for nearly a decade. The actor embedded within critical authentication systems where standard cleanup procedures could not detect it, demonstrating exceptional operational security and deep understanding of Unix/Linux system architecture.

Impact: Organizations running Linux authentication infrastructure face risk of undetected compromise spanning years. The backdooring of PAM and OpenSSH—core authentication components used across enterprise servers, cloud infrastructure, and network devices—suggests the actor seeks access to environments where these systems control access to sensitive data or critical operations. The nearly decade-long persistence timeline indicates high-value targets where long-term intelligence collection justifies operational risk.

Recommendations:

  • Implement file integrity monitoring on critical authentication components including PAM modules and OpenSSH binaries to detect unauthorized modifications.
  • Monitor for unusual network connections on non-standard ports and asymmetric encryption patterns in outbound traffic.
  • Audit external remote service access and RC script modifications, correlating authentication logs with process execution.
  • Deploy network traffic analysis to identify data encoding schemes and internal proxy behavior.
  • Conduct regular cryptographic verification of system binaries against known-good hashes from trusted repositories.

---

Threat Actor Activity

ShinyHunters/UNC6240 Zero-Day Exploitation Campaign

ShinyHunters (UNC6240 per Google Mandiant) demonstrated zero-day exploitation capability against Oracle PeopleSoft, targeting education and enterprise sectors between May 27 and June 9. The financially motivated actor has a documented history of large-scale data theft and extortion operations dating back to 2020. Organizations should review PeopleSoft deployments for compromise indicators and apply Oracle's June 10 patch immediately.

UNC1151/Ghostwriter Targets Polish Gmail Accounts

UNC1151, also tracked as Ghostwriter and attributed to Belarus with operational links to Russian intelligence, continues sustained phishing campaigns targeting Gmail accounts of Polish citizens. The multi-year campaign demonstrates tactical evolution while maintaining consistent operational objectives. Poland's CERT.PL reports the group has been attacking Polish mailboxes for several years, likely seeking intelligence collection on government, military, and civil society entities.

Velvet Ant Authentication Layer Persistence

China-linked Velvet Ant maintained covert access to compromised environments for nearly a decade by backdooring PAM and OpenSSH. The sophisticated tradecraft targeting authentication infrastructure at the operating system level demonstrates advanced persistence capabilities characteristic of state-sponsored espionage campaigns prioritizing stealth over immediate exploitation.

OceanLotus Domestic Surveillance Operations

OceanLotus (APT32), a Vietnam-aligned threat actor, conducted prolonged cyber espionage against Vietnamese infrastructure, transportation, construction, and finance sectors from mid-2024 to February 2026 using the SPECTRALVIPER backdoor. The domestic targeting pattern suggests internal surveillance and economic intelligence collection objectives, including monitoring of stock market investors.

---

Geopolitical Context

Law Enforcement Disruptions

Conti Ransomware Prosecution: A Ukrainian national extradited from Ireland pleaded guilty to conspiracy charges related to the Conti ransomware operation, marking significant international cooperation between Ukrainian, Irish, and U.S. authorities in pursuing ransomware criminals despite the group's formal disbandment in 2022.

AudiA6 Cryptocurrency Laundering Takedown: Europol disrupted AudiA6, a cryptocurrency laundering service that processed over €336 million in illicit profits for ransomware gangs and cybercriminal networks. The operation targets the financial enablement layer of the ransomware ecosystem.

Sniper Dz Phishing Platform Dismantled: INTERPOL-led Operation Ramz resulted in 201 arrests across 13 Middle East and North Africa countries, disrupting the decade-long Sniper Dz phishing-as-a-service platform and arresting its primary administrator, Guedz.

CISA Binding Operational Directive 26-04

CISA issued BOD 26-04 requiring U.S. Federal Civilian Executive Branch agencies to patch critical exploited vulnerabilities within 3 days, tightening remediation timelines in response to persistent exploitation by state-sponsored and criminal actors. The directive reflects heightened concern over vulnerabilities in enterprise access infrastructure under active exploitation.

French Government Communications Breach

Over 73,000 French public sector employee accounts were affected in a breach of Tchap, France's sovereign encrypted messaging platform. The compromise undermines confidence in domestic secure communication platforms at a time when European states are prioritizing technological autonomy and digital sovereignty.

---

Recommended Actions

Immediate (0-24 hours)

1. Patch Oracle PeopleSoft for CVE-2026-35273; hunt for compromise indicators from May 27-June 9.
2. Patch Ivanti Sentry maximum-severity RCE; isolate internet-exposed instances if patching delayed.
3. Inventory Arch Linux systems using AUR packages; rotate developer credentials on affected systems.
4. Review Linux authentication components (PAM, OpenSSH) for unauthorized modifications using file integrity monitoring.
5. Apply Fortinet FortiSandbox and Veeam Backup & Replication critical patches immediately.

Within 24-72 hours

6. Deploy Microsoft June 2025 Patch Tuesday updates (206 vulnerabilities, 33 critical) to production systems.
7. Audit AI coding agent configurations for Sentry integrations; restrict code execution permissions.
8. Review LangGraph deployments and update to latest patched version from LangChain.
9. Implement MFA on all webmail accounts, particularly for high-risk individuals in Poland and MENA regions.
10. Conduct forensic analysis on Ivanti Sentry and PeopleSoft systems for evidence of unauthorized access.

This week

11. Test npm v12 in isolated environments before production rollout; audit dependencies using install scripts.
12. Review BitLocker configurations and enable TPM + PIN authentication for enhanced pre-boot protection.
13. Establish detection for AI agent code execution patterns and Agentjacking indicators.
14. Implement network segmentation to isolate backup infrastructure and authentication systems.
15. Conduct security awareness training on phishing recognition, particularly for Polish users and MENA organizations.

---

Watch List

  • OpenClaw AI agent prompt injection vulnerabilities (vCard/location pin vectors) — monitor for vendor patches.
  • phpBB authentication bypass (10-year-old flaw) — update all forum installations immediately.
  • The Gentlemen ransomware — 478 claimed victims, worm-like spreading capabilities.
  • GreatXML BitLocker bypass — monitor for Microsoft security updates addressing recovery partition XML exploitation.
  • Novo Nordisk clinical trial data breach — watch for regulatory enforcement and patient notification developments.
  • University of Nottingham breach (450,000+ records) — monitor for ICO investigation and potential enforcement action.
  • Kyushu Electric Power data loss (10.9M customer records) — track Japanese regulatory response and recovery efforts.
  • Coupang record fine ($409M in South Korea) — potential precedent for Asia-Pacific data protection enforcement.

---

Sources

  • BleepingComputer: Oracle PeopleSoft, Ivanti Sentry, Arch Linux AUR, Conti guilty plea, French Tchap breach, Novo Nordisk, Coupang fine, University of Nottingham, Japanese energy firm, AudiA6 takedown, CISA BOD 26-04, phpBB
  • The Hacker News: ShinyHunters/UNC6240, Velvet Ant, Agentjacking, LangGraph, INTERPOL Operation Ramz, Europol AudiA6, Google v. Chinese smishing network, OpenClaw, GreatXML, The Gentlemen ransomware, OceanLotus, npm v12
  • CERT.BE (Belgium): Fortinet FortiSandbox, Veeam Backup & Replication, Microsoft Patch Tuesday June 2025, Ivanti Sentry
  • CERT.PL (Poland): UNC1151/Ghostwriter Gmail campaign

---

*This brief covers events reported through June 13, 2026. Threat intelligence is time-sensitive; verify current status of vulnerabilities and threat actor activity before taking action.*