ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google says
On September 25, Google's cybersecurity team reported that the hacking group ShinyHunters has resumed unauthorized exploitation of a vulnerability in Oracle's PeopleSoft software, following the implementation of security measures put in place after previous attacks in the summer. According to a threat intelligence report by Mandiant, ShinyHunters targeted organizations between May 27 and June 9, primarily affecting universities, after initially evading defenses.
The attackers adapted their methods to evade web application firewall rules, despite an update released by Oracle to address the vulnerability. The recent attack impacted numerous systems across various industries, including higher education, technology, healthcare, agriculture, transportation, and government. While ShinyHunters claimed responsibility for accessing FBI personnel data, this assertion has not been independently verified by Reuters.
The Federal Bureau of Investigation has since launched an aggressive investigation into the reported breach. ShinyHunters reportedly stole FBI personnel information, including names, as well as medical and psychiatric records of sensitive FBI employees.
Written by urgent.news from Investing.com's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- ShinyHunters hackers expanded attacks on Oracle’s PeopleSoft, Google says investing.com
- Google says ShinyHunters has renewed "mass exploitation" of a flaw in Oracle's PeopleSoft; ShinyHunters has said it accessed FBI data using a flaw in PeopleSoft (Reuters) reuters.com
- ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google says channelnewsasia.com