Mandiant reports ShinyHunters has resumed global cyber attacks exploiting Oracle PeopleSoft vulnerabilities.

Google’s Mandiant says the ShinyHunters hacking group has resumed mass exploitation of a vulnerability in Oracle PeopleSoft, adapting its tactics to target organizations that added web application firewall rules but did not install Oracle’s security update. The latest campaign affected dozens of systems worldwide across sectors including higher education, technology, health care, agriculture, transportation and government; an earlier wave mainly hit universities. ShinyHunters has claimed it used the flaw to access FBI data, and reports say the group disclosed names of personnel in sensitive units and obtained medical and psychiatric records. The FBI says it is investigating the reported breach, but the claim of access to its data has not been independently verified, and Oracle did not comment.
Mandiant said the earlier wave of attacks ran from May 27 through June 9.
Mandiant’s threat-intelligence report announcing the renewed campaign came several days after ShinyHunters claimed it had accessed FBI data.
PeopleSoft is widely used to manage payroll, human-resources and student data, which makes it a high-value target for attackers, according to the article.
Publishers
18
Articles
47
Reach
65