The perimeter is the platforms you trust: PeopleSoft, Splunk and a poisoned plugin store
A single Oracle PeopleSoft zero-day cascades into 100+ organisations including a US regulator. A CVSS 9.8 flaw turns Splunk, the defender's own eyes, into an attack surface with a three-day federal patch deadline. And a plugin-store supply chain harvests the AI API keys of nearly 70,000 developers.
Executive summary
- The perimeter is now the platforms you trust most. A PeopleSoft zero-day cascaded into 100+ victim organisations; a pre-auth Splunk flaw made the SIEM itself the attack surface; a developer marketplace shipped credential stealers for eight months.
- A regulator's core function was suspended by a breach. The US NAIC paused publishing investment risk designations after rating agencies cut data feeds, systemic third-party risk in one incident.
- AI sits on both sides of the ledger. Attackers harvested developers' AI API keys at scale, while a phishing-as-a-service ring used Gemini to generate credential-harvesting pages across 1.59 million fraudulent URLs.
Key findings
PeopleSoft zero-day cascades into 100+ organisations, education hardest hit
A CVSS 9.8 unauthenticated RCE in Oracle PeopleSoft was exploited as a zero-day from late May before Oracle's emergency 10 June advisory. The extortion crew behind it claims roughly 300 compromised instances across 100+ organisations, 68% in higher education; the University of Nottingham confirmed over 40 GB leaked covering ~454,600 students. Post-exploitation included automated SSH credential-spraying scripts.
Splunk Enterprise pre-auth flaw exploited within days; CISA orders a 3-day patch
A CVSS 9.8 missing-authentication flaw in Splunk Enterprise's PostgreSQL sidecar allows unauthenticated file writes chainable to remote code execution. Exploitation began days after the 12 June public write-up; CISA added it to KEV on 18 June with a patch deadline of Sunday 21 June. A compromised SIEM is a compromise of the defender's own visibility layer.
15 fake AI plugins on the JetBrains Marketplace stole AI API keys from ~70,000 developers
Malicious plugins masquerading as AI coding assistants, published under seven vendor accounts since October 2025, exfiltrated OpenAI, DeepSeek and SiliconFlow API keys. JetBrains removed the plugins and remotely disabled installed copies. Supply-chain targeting has shifted to the AI-credential layer of developer environments.
Microsoft's largest-ever Patch Tuesday: 200 flaws, six zero-days, one exploited
The June release fixed 200 vulnerabilities (some trackers count 206), the largest Patch Tuesday since the programme began in 2003, including an actively exploited Exchange Server flaw enabling script execution in Outlook Web Access, two BitLocker bypasses and an HTTP/2 denial-of-service bug.
Ransomware halts a national sugar producer; a US regulator suspends a core function
A ransomware attack shut the mills of Australia's second-largest sugar producer at the start of crushing season, stalling 1,300+ farms. Separately, the US NAIC, breached via the same PeopleSoft flaw, paused publishing investment risk designations after rating agencies suspended data feeds: a cyber incident at a regulator directly halting a regulatory function.
The broader pattern
- Trusted platforms are the initial-access vector of the season. ERP, the SIEM and a developer marketplace all served as the front door this fortnight; detection has to assume the platform itself can turn hostile.
- Disclosure-to-exploitation is now measured in days. Splunk went from write-up to in-the-wild exploitation inside a week, and CISA's three-day federal deadline reflects the new tempo.
- Machine identities and AI credentials are prime loot. API keys, service accounts and connected apps deserve the same monitoring rigour as human logins.
Sector lens
Suggested priorities to consider
Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.
If you run Oracle PeopleSoft, patch CVE-2026-35273 and hunt back to late May. Exploitation predated the advisory by two weeks; look for SSH credential-spraying fanout and extortion marker files.
Patch Splunk Enterprise (CVE-2026-20253) and audit the SIEM's own attack surface. Your visibility layer is a tier-0 asset: restrict exposure, monitor it like a domain controller.
Inventory IDE plugins across engineering and rotate any exposed AI API keys. Treat marketplace plugins as third-party software with the same vetting as any vendor.
Prioritise the June Patch Tuesday Exchange zero-day on internet-facing OWA. One flaw in the set was already being exploited before release day.
Add machine-identity anomalies to detection coverage. Service accounts, API keys and connected apps were the common thread across every major incident this fortnight.
These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.
Blacklight treats the platforms you depend on as first-class telemetry, ERP, SIEM-adjacent infrastructure, identity and SaaS, and its agents baseline every machine identity alongside the humans. When a KEV entry lands, it is correlated against your actual estate the same day, and anomalous service-account or API-key behaviour is investigated autonomously, with the full reasoning trail shown.
Sources & methodology
Primary public sources this issue: Google Threat Intelligence Group / Mandiant (PeopleSoft campaign reporting) · Oracle Security Alert for CVE-2026-35273 · CISA Known Exploited Vulnerabilities catalog and alerts (8, 9 and 18 June 2026) · Microsoft June 2026 Patch Tuesday release notes with BleepingComputer, CyberScoop and Malwarebytes coverage · JetBrains Marketplace security update (16 June 2026) · Novo Nordisk incident disclosure · NAIC security update · The Record, SecurityWeek and The Register incident reporting · MITRE ATT&CK v15 for technique mapping.