The University of Nottingham disclosed that attackers accessed its student records platform and exposed records for 454,600 current and former students. ShinyHunters asserted responsibility as part of an ongoing campaign that has hit over 100 organizations through Oracle PeopleSoft vulnerabilities.

The group has stolen data from over 100 organizations worldwide after breaching their cloud and on-premises Oracle PeopleSoft instances.
ShinyHunters told BleepingComputer that they are using a "gadget chain" of zero-days and old vulnerabilities in the attacks.
Universities remain prime targets for credential-stuffing and zero-day gadget chains against legacy PeopleSoft deployments; institutions should prioritize configuration hardening and third-party platform audits to limit lateral movement.
Tap a lens to see what this story means for you.
Reader-supported · The Brief
Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Apple is preparing an "Apple Upgrade" leasing program with Klarna for a July 28 debut in the U.S. while lifting Apple Music and related subscription costs. The period also delivered iOS 27 beta 4, plans for roughly a dozen new Macs according to Bloomberg's Mark Gurman, and hands-on impressions of Samsung's Galaxy Z Fold8.
OpenAI confirms ChatGPT is down worldwide. The outage began at approximately 5 AM ET on July 25, 2026, preventing users from loading chats or accessing previous conversations.
Microsoft disclosed CVE-2026-56163, a critical vulnerability in Azure Kubernetes Service with a CVSS 3.1 score of 10.0 that allows unauthorized network-based privilege elevation. The flaw was received from Microsoft on July 24, 2026 and requires immediate attention from Azure Kubernetes users to prevent high-impact compromise.