
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

Reuters – Google’s cybersecurity unit said on Friday that hacking group ShinyHunters has renewed “mass exploitation” of a security flaw in Oracle’s PeopleSoft software, after skirting defenses put up following attacks in the summer.
Summary
Mandiant made the announcement in a threat intelligence report released days after ShinyHunters, which has claimed responsibility for several major data breaches, said it had stolen FBI personnel data . The evolving nature of the attack is likely to ring alarm bells at organizations that rely on PeopleSoft for human resources and other critical functions, and heighten concerns about the vulnerability of even well-resourced institutions. The unit of Alphabet’s (GOOGL.O) , opens new tab Google said ShinyHunters exploited a bug in Oracle’s (ORCL.N) , opens new tab PeopleSoft enterprise software in attacks from May 27 through June 9 that mainly affected universities.
Mandiant said the hackers adapted to defensive guidance published after the May-June attacks and targeted organizations that implemented web application firewall rules but did not apply an update that Oracle issued to patch the vulnerability. It said, without identifying victims, that the latest attack affected dozens of systems globally in sectors as varied as higher education, technology, healthcare, agriculture, transportation and government. ShinyHunters has said it accessed FBI data using a vulnerability in PeopleSoft.
Reuters has not been able to corroborate the claim. Oracle did not respond to requests for comment. In a statement issued Wednesday, the Federal Bureau of Investigation said it was “aggressively investigating” the reported breach.
ShinyHunters exposed the names of personnel working in sensitive FBI units and acquired medical and psychiatric records, Reuters previously reported.
KazaSec's take
Incidents like this rarely start with the headline event itself — they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
We've archived 57 other articles touching the same topic (top news) — see the full security news archive.
Related security advisories
Relevant from KazaSec
More coverage on this topic
We help organizations find and fix the gaps before they make headlines.