The University of Nottingham disclosed that attackers accessed its student records platform and exposed records for 454,600 current and former students. ShinyHunters asserted responsibility as part of an ongoing campaign that has hit over 100 organizations through Oracle PeopleSoft vulnerabilities.

The group has stolen data from over 100 organizations worldwide after breaching their cloud and on-premises Oracle PeopleSoft instances.
ShinyHunters told BleepingComputer that they are using a "gadget chain" of zero-days and old vulnerabilities in the attacks.
Universities remain prime targets for credential-stuffing and zero-day gadget chains against legacy PeopleSoft deployments; institutions should prioritize configuration hardening and third-party platform audits to limit lateral movement.
Tap a lens to see what this story means for you.
Reader-supported · Daily Brief
Daily brief at 7 AM ET. Top tech stories, every morning. Sourced and fact-checked.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
ChangXin Memory Technologies expects to raise 57.9 billion yuan ($8.55 billion) in its Shanghai STAR Market IPO after doubling its original target. The world's fourth-largest DRAM chipmaker will list on July 27, advancing China's push for semiconductor self-reliance.
CISA added CVE-2023-4346 affecting KNX Association KNX Protocol Connection Authorization Option 1 to its Known Exploited Vulnerabilities catalog on 2026-07-15. Federal agencies must finish remediation by 2026-07-29. The overly restrictive account lockout mechanism could let attackers purge devices and set a BCU key when extra security options remain disabled, so organizations must apply vendor mitigations under BOD 26-04.
Bloomberg reports that OnePlus will exit the U.S. and European smartphone markets as part of restructuring at owner Oppo, with the move possibly starting as soon as this week. The brand's earlier popularity has faded while Chinese suppliers face mounting pressure from memory chip costs and declining shipments in key regions.