Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025
Security Vulnerabilities

ShinyHunters Exploits Oracle PeopleSoft Zero-Day, Breaches 100+ Organizations

A critical unauthenticated remote code execution flaw in Oracle PeopleSoft PeopleTools was weaponized as a zero-day by the ShinyHunters extortion group between late May and early June 2026, with higher education institutions accounting for roughly two-thirds of confirmed victims.

ShinyHunters Exploits Oracle PeopleSoft Zero-Day, Breaches 100+ Organizations
panumas nikhomkhai · Pexels

Mandiant and Google's Threat Intelligence Group (GTIG) have linked an extortion campaign running from May 27 to June 9, 2026 to the threat actor tracked as UNC6240, publicly known as ShinyHunters. The group exploited CVE-2026-35273, a CVSS 9.8 remote code execution flaw in the Environment Management component of Oracle PeopleSoft PeopleTools, before Oracle published its security advisory on June 10 — confirming the vulnerability was used as a zero-day.

Oracle has since acknowledged that PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 are affected and has released emergency mitigations while a full patch is in preparation. The flaw requires no authentication to exploit and can yield complete remote code execution on vulnerable instances.

Key facts
  • CVE-2026-35273 carries a CVSS base score of 9.8 (critical)
  • Affected versions: PeopleSoft Enterprise PeopleTools 8.61 and 8.62
  • Activity window: May 27 – June 9, 2026; Oracle advisory issued June 10, 2026
  • More than 100 organizations notified; 68% in higher education
  • ShinyHunters claims data stolen from 300 instances across those organizations

GTIG researchers identified five sequential staging IPs (142.11.200.186–.190) running Python SimpleHTTP servers on port 8888, which inadvertently exposed attacker tooling, command histories, and prebuilt agent binaries. Those binaries were MeshCentral remote management agents compiled for Windows and disguised as Microsoft Azure services — the executables carried names like meshagent64-azure-ops.exe and were hardcoded to call back to a command-and-control domain, azurenetfiles.net, chosen to mimic legitimate Azure NetApp Files infrastructure. A Let's Encrypt certificate for that domain was provisioned automatically via the acme-client npm package within minutes of the staging server being stood up.

The exposed .bash_history files, identical across all five hosts, gave investigators a detailed timeline of attacker operations. After establishing the C2 environment, the group used MeshCentral's CLI tool to run reconnaissance commands on victim hosts — querying PeopleSoft process scheduler configurations, WebLogic XML files, and internal network mounts. Lateral movement was carried out by a custom shell script, named with a victim-specific abbreviation followed by _fanout.sh, which parsed internal hostnames, attempted SSH credential spraying using hardcoded username-password pairs, and deposited a ransom-note file (README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT) into WebLogic and Process Scheduler directories. Exfiltrated data was compressed with zstd before the staging host connected outbound to 176.120.22.24, the server hosting the public ShinyHunters data leak site.

Data from compromised organizations appeared on that leak site on June 9, 2026 — the same day open attacker directories were publicly flagged by researcher @nahamike01 on X, prompting GTIG's detailed triage.

ShinyHunters confirmed to BleepingComputer that they are responsible, describing the attack chain as a combination of older vulnerabilities and the new zero-day. The group has previously been connected to large-scale breaches of Snowflake-hosted data and Salesforce environments, as well as a recent intrusion at Instructure Canvas that reportedly led to a ransom payment.

For professionals

For professionals: PeopleSoft administrators should immediately block external access to /PSEMHUB/hub and /PSIGW/HttpListeningConnector at the network perimeter — WAF body-inspection rules alone are insufficient. Audit WebLogic application directories for unexpected .jsp files, check PSEMHUB.war transaction folders for unauthorized binaries, and monitor outbound SMB traffic (TCP 445) from PeopleSoft hosts, as the exploit chain may attempt NetNTLM hash capture via forced outbound connections.

Google SecOps customers will receive detection rules covering PeopleSoft configuration inspection, suspicious JSP writes to PSEMHUB, sshpass-based file deployment, zstd compression activity, and MeshCentral command execution via meshctrl.

Oracle has not publicly confirmed active exploitation in its advisory, but both Mandiant's telemetry and ShinyHunters' own statements corroborate ongoing attacks. Organizations on versions 8.61 or 8.62 should treat mitigation as urgent pending the forthcoming patch.

Discussion · coming soon

Be the first to join the thread when community discussion launches.