Urgent.News

What's breaking now, across thousands of outlets.

Tech

ShinyHunters hackers expanded attacks on Oracle’s PeopleSoft, Google says

ShinyHunters hackers expanded attacks on Oracle’s PeopleSoft, Google says

On September 25, Google's cybersecurity team reported that the hacking group ShinyHunters has resumed unauthorized exploitation of a vulnerability in Oracle's PeopleSoft software, following the implementation of security measures put in place after previous attacks in the summer. According to a threat intelligence report by Mandiant, ShinyHunters targeted organizations between May 27 and June 9, primarily affecting universities, after initially evading defenses.

The attackers adapted their methods to evade web application firewall rules, despite an update released by Oracle to address the vulnerability. The recent attack impacted numerous systems across various industries, including higher education, technology, healthcare, agriculture, transportation, and government. While ShinyHunters claimed responsibility for accessing FBI personnel data, this assertion has not been independently verified by Reuters.

The Federal Bureau of Investigation has since launched an aggressive investigation into the reported breach. ShinyHunters reportedly stole FBI personnel information, including names, as well as medical and psychiatric records of sensitive FBI employees.

Written by urgent.news from Investing.com's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 2 other outlets

Read the original at investing.com →

More in Tech

Detecting Anomalies in CI/CD Pipelines with ML

The pipeline fails. Again. Your CI run turns red. You open the logs, scroll through a wall of output, and fifteen minutes later find the answer: it's that flaky test again — the one everyone…

  • PipelineSentinel monitors CI/CD pipelines by scoring each run against its own history.
  • Python code snippet shows implementation with 'contamination' parameter for expected anomalies.

What belongs in a Plane Page, and what belongs in a Work Item?

The more thoroughly you describe a feature, the longer its Work Item becomes. Background, future plans, acceptance criteria, and test results accumulate in one description.

  • Work Items focus on specific implementation tasks
  • Shared rules and rationale belong in a Page
  • Acceptance criteria and test results in Work Item

MemTensor MemOS Supply Chain Attack: sckit Triggered by Python Imports and OpenClaw Runtime Hooks

1. Basic Information Original Title: The AI Ecosystem Has Worms Now: Inside the MemTensor Compromise Source: Semgrep Published Date: September 23, 2026 Updated Date: None Severity: critical Severity…

  • Malicious code sckit embedded in MemTensor npm, PyPI distributions
  • Attack triggered by Python imports, OpenClaw runtime hooks
  • Attackers exfiltrate credentials, access SSH keys, SaaS service tokens

File Change Notification Side Channel: Estimating Keystroke Timing and Browsing Activity on Linux, Android, and Windows

1. Overview Original Title: File Notification Attacks: Side-Channel Leakage from the File-Notification System on Linux, Android, Windows, and macOS Source: Graz University of Technology (File…

  • Researchers demonstrated estimating user activities via file change notifications.
  • Method applicable to Linux, Android, and Windows systems.
  • Attack possible without privileged access or explicit permission.

More from Saturday 26 September →