Oracle released emergency mitigations for CVE-2026-35273, a critical unauthenticated remote code execution zero-day in PeopleSoft PeopleTools 8.61 and 8.62 that ShinyHunters exploited to steal data from 300 instances across more than 100 organizations. The flaw carries a 9.8 CVSS score and highlights ongoing risks to enterprise platforms hosting sensitive corporate data.

ShinyHunters used the zero-day to breach over 100 organizations.
The group left ransom notes on compromised instances and claimed to use a gadget chain of old and zero-day flaws.
Enterprise security teams should treat this as an immediate patching priority and scan logs for the listed IPs, as the gap between zero-day disclosure and widespread exploitation continues to shrink for legacy enterprise suites.
Tap a lens to see what this story means for you.
Reader-supported · The Brief
Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Microsoft disclosed CVE-2026-57990, a high-severity vulnerability in Chromium-based Edge that lets unauthorized attackers disclose information by accessing external files or directories over a network. The CVSS 7.4 flaw, published July 26 2026, underscores the need for prompt patching in widely deployed browsers.
Microsoft disclosed CVE-2026-57989, a high-severity origin validation error in Chromium-based Edge that lets an unauthorized attacker disclose information over a network. The flaw is rated CVSS 7.4 and affects versions before 150.0.4078.99.
SpaceX plans to attempt catching its Starship spacecraft with mechanical tower arms on the next test flight following a successful ocean landing on Flight 13. The milestone would advance the vehicle's reusability after demonstrating satellite deployment and an in-flight engine restart.