Skip to content
All resources
Cybersecurity Intel · № 12 · 8 – 21 June 2026

The perimeter is the platforms you trust: PeopleSoft, Splunk and a poisoned plugin store

A single Oracle PeopleSoft zero-day cascades into 100+ organisations including a US regulator. A CVSS 9.8 flaw turns Splunk, the defender's own eyes, into an attack surface with a three-day federal patch deadline. And a plugin-store supply chain harvests the AI API keys of nearly 70,000 developers.

Published 22 June 2026 By Blacklight Threat Intelligence Classification TLP:CLEAR · Public
200
Flaws in Microsoft's largest-ever Patch Tuesday, incl. 6 zero-days
100+
Organisations hit via one Oracle PeopleSoft zero-day (CVE-2026-35273)
~70k
Installs of credential-stealing JetBrains Marketplace AI plugins
3 days
CISA's remediation window for the exploited Splunk CVSS 9.8 flaw

Executive summary

  • The perimeter is now the platforms you trust most. A PeopleSoft zero-day cascaded into 100+ victim organisations; a pre-auth Splunk flaw made the SIEM itself the attack surface; a developer marketplace shipped credential stealers for eight months.
  • A regulator's core function was suspended by a breach. The US NAIC paused publishing investment risk designations after rating agencies cut data feeds, systemic third-party risk in one incident.
  • AI sits on both sides of the ledger. Attackers harvested developers' AI API keys at scale, while a phishing-as-a-service ring used Gemini to generate credential-harvesting pages across 1.59 million fraudulent URLs.

Key findings

10 – 11 June 2026 CVE-2026-35273 · ATT&CK T1190

PeopleSoft zero-day cascades into 100+ organisations, education hardest hit

A CVSS 9.8 unauthenticated RCE in Oracle PeopleSoft was exploited as a zero-day from late May before Oracle's emergency 10 June advisory. The extortion crew behind it claims roughly 300 compromised instances across 100+ organisations, 68% in higher education; the University of Nottingham confirmed over 40 GB leaked covering ~454,600 students. Post-exploitation included automated SSH credential-spraying scripts.

18 June 2026 CVE-2026-20253 · KEV

Splunk Enterprise pre-auth flaw exploited within days; CISA orders a 3-day patch

A CVSS 9.8 missing-authentication flaw in Splunk Enterprise's PostgreSQL sidecar allows unauthenticated file writes chainable to remote code execution. Exploitation began days after the 12 June public write-up; CISA added it to KEV on 18 June with a patch deadline of Sunday 21 June. A compromised SIEM is a compromise of the defender's own visibility layer.

16 June 2026 ATT&CK T1195.002

15 fake AI plugins on the JetBrains Marketplace stole AI API keys from ~70,000 developers

Malicious plugins masquerading as AI coding assistants, published under seven vendor accounts since October 2025, exfiltrated OpenAI, DeepSeek and SiliconFlow API keys. JetBrains removed the plugins and remotely disabled installed copies. Supply-chain targeting has shifted to the AI-credential layer of developer environments.

9 June 2026 Patch Tuesday

Microsoft's largest-ever Patch Tuesday: 200 flaws, six zero-days, one exploited

The June release fixed 200 vulnerabilities (some trackers count 206), the largest Patch Tuesday since the programme began in 2003, including an actively exploited Exchange Server flaw enabling script execution in Outlook Web Access, two BitLocker bypasses and an HTTP/2 denial-of-service bug.

10 – 18 June 2026 OT / systemic risk

Ransomware halts a national sugar producer; a US regulator suspends a core function

A ransomware attack shut the mills of Australia's second-largest sugar producer at the start of crushing season, stalling 1,300+ farms. Separately, the US NAIC, breached via the same PeopleSoft flaw, paused publishing investment risk designations after rating agencies suspended data feeds: a cyber incident at a regulator directly halting a regulatory function.

The broader pattern

  • Trusted platforms are the initial-access vector of the season. ERP, the SIEM and a developer marketplace all served as the front door this fortnight; detection has to assume the platform itself can turn hostile.
  • Disclosure-to-exploitation is now measured in days. Splunk went from write-up to in-the-wild exploitation inside a week, and CISA's three-day federal deadline reflects the new tempo.
  • Machine identities and AI credentials are prime loot. API keys, service accounts and connected apps deserve the same monitoring rigour as human logins.

Sector lens

Education
68% of PeopleSoft zero-day victims were universities; student PII at registrar scale is now standard extortion inventory. If you run PeopleSoft, treat compromise as presumed until hunted.
Insurance
The NAIC breach shows regulator-side incidents can suspend functions your capital planning depends on. Map third-party dependencies that sit above you, not just below.
Pharma & healthcare
Double-extortion against a global pharma major included pseudonymised clinical-trial data; two crews demanded eight-figure ransoms. Crown-jewel data inventories should include trial and research sets.
Manufacturing & agriculture
The sugar-mill shutdown is the OT pattern in miniature: IT-side ransomware halting physical production at the worst seasonal moment.
Technology & software
If your developers install IDE plugins, assume marketplace supply-chain risk: inventory plugins, rotate exposed AI API keys, and alert on anomalous key usage.

Suggested priorities to consider

Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.

01

If you run Oracle PeopleSoft, patch CVE-2026-35273 and hunt back to late May. Exploitation predated the advisory by two weeks; look for SSH credential-spraying fanout and extortion marker files.

02

Patch Splunk Enterprise (CVE-2026-20253) and audit the SIEM's own attack surface. Your visibility layer is a tier-0 asset: restrict exposure, monitor it like a domain controller.

03

Inventory IDE plugins across engineering and rotate any exposed AI API keys. Treat marketplace plugins as third-party software with the same vetting as any vendor.

04

Prioritise the June Patch Tuesday Exchange zero-day on internet-facing OWA. One flaw in the set was already being exploited before release day.

05

Add machine-identity anomalies to detection coverage. Service accounts, API keys and connected apps were the common thread across every major incident this fortnight.

These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.

How Blacklight handles this

Blacklight treats the platforms you depend on as first-class telemetry, ERP, SIEM-adjacent infrastructure, identity and SaaS, and its agents baseline every machine identity alongside the humans. When a KEV entry lands, it is correlated against your actual estate the same day, and anomalous service-account or API-key behaviour is investigated autonomously, with the full reasoning trail shown.

Book a Demo

Sources & methodology

Primary public sources this issue: Google Threat Intelligence Group / Mandiant (PeopleSoft campaign reporting) · Oracle Security Alert for CVE-2026-35273 · CISA Known Exploited Vulnerabilities catalog and alerts (8, 9 and 18 June 2026) · Microsoft June 2026 Patch Tuesday release notes with BleepingComputer, CyberScoop and Malwarebytes coverage · JetBrains Marketplace security update (16 June 2026) · Novo Nordisk incident disclosure · NAIC security update · The Record, SecurityWeek and The Register incident reporting · MITRE ATT&CK v15 for technique mapping.

Methodology. Findings are compiled from public reporting and Blacklight Threat Intelligence monitoring for the stated window, mapped to MITRE ATT&CK where applicable. Aggregate platform observations, where cited, are anonymised across the Blacklight customer base and never identify a customer environment. Corrections: intel@blacklightai.com.

Related reading

Blacklight AI · Cybersecurity Intel · № 12 TLP:CLEAR
Get started

See what truly predictive
security looks like.

Sixty minutes, under your control. See the platform run on a pre-loaded, anonymised environment, watch one real incident handled end to end, and map it to your sector, without connecting a single data source.

A typical demo
  • 01 A live tour on a pre-loaded, anonymised environment, running from minute one, not slides.
  • 02 One real incident, detected, investigated and contained, written up as a regulator-ready report.
  • 03 Mapped to your world: your sources, your sector's threats and your regulators.
  • 04 The questions your board will ask: deployment, residency, security, integrations and TCO.

No connectors or data required from you. A proof-of-value on your own telemetry is the next step, never the ask on a first call.