ShinyHunters hackers expanded attacks on Oracle’s PeopleSoft, Google says
Google's cybersecurity unit reported on Friday that the hacking group ShinyHunters has resumed a campaign targeting a security flaw in Oracle's PeopleSoft software, following earlier attacks in June. Security firm Mandiant revealed this in a threat intelligence report published days after ShinyHunters claimed responsibility for stealing FBI personnel data.
The evolving nature of these attacks is expected to cause concern for organizations that depend on PeopleSoft for critical operations, such as human resources management.
ShinyHunters exploited a vulnerability in Oracle's PeopleSoft enterprise software between May 27 and June 9, primarily affecting universities. The hackers adapted their tactics to bypass defensive measures recommended after the initial attacks and targeted organizations that implemented web application firewall rules but failed to install the necessary Oracle patch to fix the vulnerability.
Although Mandiant did not disclose specific victim information, it stated that the latest attack impacted systems across various industries, including higher education, technology, healthcare, agriculture, transportation, and government.
ShinyHunters allegedly obtained FBI personnel data using the exploited PeopleSoft vulnerability. However, Reuters has been unable to verify this claim. Oracle has not yet responded to inquiries regarding the issue. In a statement released on Wednesday, the Federal Bureau of Investigation confirmed that it is conducting a thorough investigation into the reported breach.
ShinyHunters reportedly accessed sensitive FBI personnel records, including names of employees in sensitive units, as well as medical and psychiatric information, according to Reuters earlier.
Written by urgent.news from The Indian Express's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- ShinyHunters hackers expanded attacks on Oracle’s PeopleSoft, Google says investing.com
- Google says ShinyHunters has renewed "mass exploitation" of a flaw in Oracle's PeopleSoft; ShinyHunters has said it accessed FBI data using a flaw in PeopleSoft (Reuters) reuters.com
- ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google says channelnewsasia.com