Chrome 0-Day, ShinyHunters Oracle Attack & Arch Linux Supply Chain Hit
Google has rolled out emergency security updates for Chrome to patch CVE-2026-11645, a high-severity out-of-bounds memory access vulnerability in the V8 JavaScript and WebAssembly engine. Rated 8.8 on the CVSS scale, the flaw is confirmed to be under active exploitation in the wild, though Google withheld technical specifics to give users time to update before attackers can weaponize them. The fix is part of a broader 74-vulnerability release and marks the fifth Chrome zero-day patched this year, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, and CVE-2026-5281. Users are urged to verify their browser version and update immediately, and to check their overall exposure with a privacy checkup to confirm no stale sessions remain.
The ShinyHunters extortion group, tracked by Google Mandiant as UNC6240, exploited an unauthenticated critical flaw in Oracle PeopleSoft Enterprise PeopleTools to breach enterprise networks across the U.S. higher education sector. The vulnerability, CVE-2026-35273, carries a near-maximum CVSS score of 9.8 and stems from a missing authentication check on the PSEMHUB Environment Management Hub endpoint. Between May 27 and June 9, 2026, attackers used MeshCentral for internal reconnaissance, performed lateral movement, exfiltrated data, and then published the stolen records on the ShinyHunters Data Leak Site. CISA has added the bug to its Known Exploited Vulnerabilities catalog with a June 15, 2026 remediation deadline for federal agencies. Organizations running legacy PeopleSoft deployments should audit exposed services using a port scanner and verify that no credentials surfaced in the leak, which can be confirmed with an email breach checker.
The supply chain threat also escalated this week after attackers compromised hundreds of Arch Linux packages in the official repositories to distribute a rootkit and information stealer to unsuspecting users. This campaign highlights the continued risk of trusting upstream maintainers and abandoned packages that remain active in production environments, a recurring theme in 2026 incidents. Security teams are being reminded that deprecated features, forgotten software, and unrotated credentials remain the easiest entry points for modern threat actors. Defenders should enforce strict dependency pinning, monitor package integrity, and revisit exposed login paths before the next abandoned component becomes someone else's initial access vector.