Google says ShinyHunters has renewed "mass exploitation" of a flaw in Oracle's PeopleSoft; ShinyHunters has said it accessed FBI data using a flaw in PeopleSoft (Reuters)
Google's cybersecurity unit said on Friday that hacking group ShinyHunters has renewed “mass exploitation” …
Google's cybersecurity unit, Mandiant, has reported that the hacking group ShinyHunters has resumed "mass exploitation" of a security flaw in Oracle's PeopleSoft software. According to Mandiant, ShinyHunters adapted to defensive measures put in place after previous attacks and targeted organizations that had implemented web application firewall rules but not applied an update to patch the vulnerability.
The latest attacks, which affected dozens of systems globally, hit various sectors including higher education, technology, healthcare, agriculture, transportation, and government. Investing.com reports that the attacks mainly occurred after ShinyHunters claimed responsibility for stealing FBI personnel data using the same vulnerability in PeopleSoft.
Mandiant previously reported that ShinyHunters exploited the bug in Oracle's PeopleSoft enterprise software in attacks from May 27 through June 9, mainly affecting universities. The group has reportedly accessed FBI data using a vulnerability in PeopleSoft, as stated by ShinyHunters themselves.
Brief written by urgent.news from Techmeme, Investing.com — 2 reports on this story. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.