CVE-2026-35273 in Oracle PeopleSoft was leveraged to extort over 100 organisations; Google identified 68% of targets in the higher education sector with stolen data exceeding 40 GB.
The GreatXML exploit leverages a security vulnerability in Microsoft’s offline scan function to bypass BitLocker and access encrypted drives from recovery mode after a successful Defender offline scan.
Only 5% of CISOs prioritize the “Harvest Now, Decrypt Later” threat despite second-highest concern about quantum computing, while standards for quantum-resistant encryption are available from 2024.
Oracle has patched a critical vulnerability in PeopleSoft Suite (CVE-2026-35273) enabling unauthenticated remote code execution that is already being actively exploited in targeted data theft campaigns by the ShinyHunter group.